Rundll32 Proxy Execution via DLL from Non-Standard Path (T1218.011)
Detects instances of rundll32.exe being used to load DLL, OCX, or CPL files from suspicious locations such as user-writable directories (Temp, AppData, Downloads, etc.) or UNC paths. This behavior is indicative of an adversary attempting to execute malicious code using a trusted Windows system binary (LOLBin).
SentinelOne

