rnpkeys.exe side-loads rnp.dll/tdwp.dll before anti-sandbox delay
Detects the execution of the Sauron Loader malware, which utilizes a DLL side-loading chain involving rnpkeys.exe loading rnp.dll or tdwp.dll from a specific ProgramData path, indicating potential malicious activity.
Sigma

