Mshta.exe Remote HTA Execution via URL (T1218.005)

Detects execution of mshta.exe with a command-line containing a URL, which is a common technique used by attackers to proxy the execution of remote malicious payloads such as HTA, VBScript, or JScript files. The rule excludes common Microsoft domains to reduce false positives.