Manual PEB Ldr Walk & DLL Export Parsing Evading LoadLibrary/GetProcAddress

This rule detects processes manually resolving API function addresses by traversing the Process Environment Block (PEB) Ldr structure or parsing module export tables. This technique is often used by malicious code to resolve Windows API functions dynamically without relying on standard LoadLibrary or GetProcAddress calls, effectively evading common API-hooking based monitoring.