GlobalProtect VPN DLL Side-Loading Activity
Detects potential DLL side-loading attempts involving GlobalProtect VPN components. The rule identifies the execution of GlobalProtect.exe with specific command-line arguments combined with the presence of suspicious versions of bcrypt.dll or WININET.dll within the same directory, which are characteristic of recent malicious activity involving modified DLL files targeting GlobalProtect environments.
Microsoft Sentinel (KQL)

