MSHTA Remote Script or JS/VBS Payload Execution via T1218.005

Detects the execution of mshta.exe with command-line arguments that include remote protocols (http/https) or scripts (javascript/vbscript). This behavior is commonly associated with fileless malware execution and proxying malicious code via a trusted Windows binary.