NeedyMantis-style DLL sideload at anomalous ProgramData/ProgramFiles paths
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Microsoft Sentinel (KQL)

