vsdbg.exe DLL Side-Loading via Renamed VS Debugger
This rule detects the execution of the Visual Studio Debugger (vsdbg.exe) from suspicious locations such as Downloads, Temp, or Desktop directories. Executing development tools from these user-writable directories is often indicative of an adversary attempting to use legitimate debugging tools to facilitate process injection or malicious activity. The rule excludes legitimate executions located within the official Microsoft Visual Studio installation directory.
SentinelOne

