A0Backdoor DLL Sideloading Detection

Detects the loading of 'hostfxr.dll' from suspicious user-specific AppData folders by 'CrossDeviceService.exe' or 'Teams.exe'. This behavior can indicate an attempt to load a malicious .NET runtime, potentially for DLL hijacking or code injection, often associated with persistence or execution techniques.