DLL Side-Loading: Unsigned DLL Loaded from Non-System Directory

Detects instances where a signed executable loads an unsigned, invalid, or revoked DLL that shares the same base filename, located outside of standard Windows system directories (System32, SysWOW64, WinSxS). This behavior is characteristic of DLL search-order hijacking and side-loading attacks often employed by loaders and malware such as Cobalt Strike.