Mshta.exe Remote HTA Execution via URL (T1218.005)
Detects execution of mshta.exe with a command-line containing a URL, which is a common technique used by attackers to proxy the execution of remote malicious payloads such as HTA, VBScript, or JScript files. The rule excludes common Microsoft domains to reduce false positives.
Microsoft Sentinel (KQL)

