Suspicious Rundll32 Execution via LOLBin Abuse (T1218.011)
This rule detects potentially malicious invocations of rundll32.exe that utilize scripting protocols (javascript:, vbscript:) or suspicious execution parameters (ShellExec_RunDLL, LaunchApplication), as well as rundll32.exe executing from non-standard or user-writable directories (e.g., AppData, Temp). The rule further filters out trusted Microsoft-signed binaries to reduce noise while highlighting potential proxy execution attempts.
SentinelOne

