ClearFake DLL Side-Loading & Crypto Stealer Payload Drops

This rule monitors for file, process, and image load events associated with a set of known malicious indicators (IOCs). It specifically flags potential DLL side-loading anomalies, such as 'Secur32.dll' being loaded by 'platform_experience_helper.exe' from non-system directories, or 'platform_experience_helper.exe' executing from locations outside the standard Google application directory.