HEAVYGRAM DLL Sideloading via MicDriver or Known Implant Binaries

This rule detects the execution of specific suspicious binary names or processes loading a specific DLL from locations outside of the legitimate Windows System32 or SysWOW64 directories. This behavior is indicative of potentially malicious executables or side-loaded DLLs masquerading as system components or running from non-standard locations to evade detection.