UAT-8302 DLL Sideloading via Trusted Executables - Unsigned DLL ImageLoad
This rule detects DLL loading events where specific legitimate applications (Adobe Creative Cloud, Microsoft Edge, or Opera GX) load a DLL from their own directory where the DLL file is unsigned or has an invalid digital signature. This pattern is often indicative of DLL sideloading, where an attacker places a malicious DLL in the application's folder to be loaded by the legitimate process.
Splunk (SPL)

