Regsvr32 Squiblydoo: Remote Scriptlet or scrobj.dll Execution
Detects execution of regsvr32.exe with flags indicative of the Squiblydoo application control bypass technique. The rule monitors for the use of the /i flag to load COM scriptlets from remote URLs (http/https) or UNC paths, or the inline loading of scrobj.dll, specifically in conjunction with the silent (/s) flag. Legitimate processes signed by Microsoft are excluded from detection unless remote URL execution is involved.
SentinelOne

