Sauron Loader DLL Side-Loading via rnpkeys.exe from keyroll Directory
Detects DLL side-loading activity where the legitimate-looking process rnpkeys.exe, located in a non-standard ProgramData sub-directory, loads a malicious rnp.dll from the same directory, a behavior observed with the Sauron Loader malware.
Sigma

