DCOM Lateral Movement - dllhost.exe Spawning Suspicious Child Process

This rule monitors for suspicious child processes (like cmd.exe, powershell.exe, wscript.exe, or rundll32.exe) spawned by dllhost.exe. Dllhost.exe is typically a legitimate Windows process for COM object hosting, and it spawning command-line interpreters or administrative utilities is often indicative of malicious activity, such as process injection or lateral movement.