ClickOnce Proxy Execution via dfsvc.exe Child or Suspicious Parent (T1127.002)

This rule detects potentially malicious use of the ClickOnce process (dfsvc.exe) by monitoring for suspicious parent processes (such as rundll32.exe or mshta.exe) spawning dfsvc.exe, or dfsvc.exe spawning unexpected child processes. ClickOnce is often abused by attackers to proxy the execution of malicious code, and these patterns are indicative of such activity.