Sauron Loader DLL Side-Loading via rnpkeys.exe from keyroll Directory

Detects DLL side-loading activity where the legitimate-looking process rnpkeys.exe, located in a non-standard ProgramData sub-directory, loads a malicious rnp.dll from the same directory, a behavior observed with the Sauron Loader malware.

Sigma