DCOM Lateral Movement via MMC20/ShellWindows COM Objects

Detects instances where common Windows system processes (dllhost.exe, mmc.exe, svchost.exe) spawn known living-off-the-land binaries (LotLBin) or command-line interpreters. This behavior is often indicative of process injection or malicious activity where an adversary leverages trusted system processes to execute commands or malicious scripts.