Unsigned or Suspiciously Located DLL Load by Common Applications

This rule detects when common Windows applications (explorer.exe, svchost.exe, winword.exe, excel.exe, rundll32.exe) load DLLs that are either unsigned or located in user-writable directories (e.g., \Users\, \AppData\, \Temp\, \ProgramData\). This is a common indicator of potential DLL hijacking or side-loading attacks.