DLL Search Order Hijacking via System Binary Loading from User-Writable Path
Detects instances where common Windows processes (explorer.exe, svchost.exe, dllhost.exe) load an unsigned module (DLL) from user-writable directories, such as AppData, Downloads, or Temp folders. This behavior is a common indicator of potential DLL sideloading or malicious code execution originating from user-controlled space.
SentinelOne

