Squiblydoo: regsvr32.exe Remote Scriptlet URL via /i:http (T1218.010)

Detects the use of regsvr32.exe to load a remote COM scriptlet via a URL. This technique, commonly known as Squiblydoo, allows adversaries to bypass application whitelisting and proxy the execution of malicious code, as regsvr32.exe is a trusted Windows binary.