DLL sideloading of Umbrij via BDSubWiz/VSTestVideoRecorder/GoogleDesktop

This rule detects when specific legitimate-looking executables (BDSubWiz.exe, VSTestVideoRecorder.exe, GoogleDesktop.exe) initiate a module load from high-risk, world-writable directories such as '\Users\Public\', '\AppData\Local\Temp\', or '\Windows\Temp\'. This pattern is highly characteristic of DLL side-loading or masquerading, where an adversary uses a known benign process to load malicious code.