Files With System DLL Name In Unsuspected Locations (13c02350-4177-4e45-ac17-cf7ca628ff5e)
Detects the creation of a file with the ".dll" extension that has the name of a System DLL in uncommon or unsuspected locations. (Outisde of "System32", "SysWOW64", etc.). It is highly recommended to perform an initial baseline before using this rule in production.