Regsvr32 Remote Scriptlet Execution
Detects the use of regsvr32.exe to execute remote scripts or components via a URL (a technique often referred to as Squiblydoo). This rule flags process command lines containing /i flags combined with remote HTTP/HTTPS addresses, while excluding known management tools to reduce false positives.
Microsoft Sentinel (KQL)

