InstallUtil.exe Assembly Load from Non-Standard Path (AppLocker Bypass)

Detects execution of the Microsoft .NET installer utility (InstallUtil.exe) from non-standard locations. Adversaries often abuse InstallUtil.exe as a proxy to execute malicious code or bypass application control policies, as it is a trusted, digitally signed Microsoft binary. The rule filters out legitimate execution paths typically associated with .NET framework installations, SDKs, or system directories.