CRPx0 Self-Signed Microsoft-Impersonating Cert on New DLL/EXE
Detects the creation of new executable files (DLL or EXE) that contain a certificate subject string referencing 'Microsoft' but are located outside of the standard 'C:\Windows\' directory. This behavior is indicative of an attacker attempting to bypass trust validation mechanisms by creating binaries with self-signed, fake Microsoft certificates, a technique observed in the CRPx0 builder toolset to evade EDR and AV inspection.
YARA-L

