STAC4924 – TerminalFix / Lorem Ipsum Loader DLL Sideloading
This rule detects potential DLL sideloading by monitoring known legitimate Windows binaries that are commonly abused to load malicious DLLs from non-standard directories (i.e., not System32, SysWOW64, or WinSxS). This activity is often associated with the TerminalFix / Lorem Ipsum Loader campaign.
Microsoft Sentinel (KQL)

