InstallUtil LOLBIN Abuse - Unsigned Code Execution via /logfile=

Detects execution of the Microsoft InstallUtil.exe utility with suspicious command-line arguments (logging suppressed to file and console) where the binary is unsigned. This is a common technique used by adversaries to proxy execution of arbitrary .NET code while attempting to avoid detection and maintain stealth.