DLL Side-Loading via Signed Process Loading from User-Writable Directory

Detects instances where a digitally signed process loads a DLL file from a user-writable directory (e.g., AppData, Downloads, or Temp). This behavior is characteristic of DLL side-loading or search-order hijacking, where an adversary attempts to execute malicious code within the context of a trusted, signed application.