Unsigned or Suspiciously Located DLL Load by Common Applications
This rule detects when common Windows applications (explorer.exe, svchost.exe, winword.exe, excel.exe, rundll32.exe) load DLLs that are either unsigned or located in user-writable directories (e.g., \Users\, \AppData\, \Temp\, \ProgramData\). This is a common indicator of potential DLL hijacking or side-loading attacks.
Microsoft Sentinel (KQL)

