Regsvr32 Squiblydoo Remote COM Object or scrobj.dll Execution
Detects the execution of regsvr32.exe with command-line arguments indicative of 'Squiblydoo' style attacks, which use the signed Windows binary to proxy the execution of remote scripts or local COM scriptlets (.sct files). The rule specifically flags the use of /i with HTTP(S) URLs, loading scrobj.dll, or specific combinations of /s /u /i flags to bypass application control mechanisms.
SentinelOne

