Potential Initial Access via DLL Search Order Hijacking (dbbd9f66-2ed3-4ca2-98a4-6ea985dd1a1c)
Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.