ClickOnce Proxy Execution via dfsvc.exe or dfshim.dll with External URL
Detects the execution of ClickOnce applications (via dfsvc.exe, rundll32.exe with dfshim.dll, or by opening .application/.appref-ms files) that are being launched from a remote web or file share source. This behavior is a common technique for proxying malicious code execution.
Microsoft Sentinel (KQL)

