Masquerading VLC binaries executed from Temp/Downloads/Desktop
This rule detects the execution of 'vlc.exe' or loading of 'libvlc.dll' from common staging or user-writable directories such as Temp, Downloads, or Desktop. This pattern is commonly associated with adversary efforts to execute masquerading or portable malicious payloads, as legitimate VLC installations are typically located in Program Files.
Sigma

