Consent.exe Loading Malicious DLL Outside System Directories

Detects DLL side-loading attacks where consent.exe loads known malicious DLLs (version.dll, rtworkq.dll, wmsgapi.dll, and the older msimg32.dll) from non-standard locations. This technique is used by Shanya-packed malware including EDR Killer and CastleRAT to load malicious payloads while appearing as a legitimate Windows UAC process.