Unbacked module load indicating in-memory BOF/object linking (no on-disk path)

Detects module or image load events where the image lacks an associated on-disk path (FolderPath is empty). This behavior is indicative of in-memory code loading, such as reflective loading or the execution of Beacon Object Files (BOFs), where malicious code is mapped directly into process memory rather than loaded via the standard OS image loader.