Squiblydoo: regsvr32.exe Remote SCT/DLL Execution or Suspicious Child Spawn
Detects the abuse of the legitimate Windows binary regsvr32.exe for malicious purposes. This rule monitors for two common attack patterns: 1) The use of regsvr32.exe with specific command-line arguments (/i, /s, /u, /n) to load remote scripts (SCT files) or libraries from the internet, a technique known as 'Squiblydoo'. 2) Suspicious child processes spawned by regsvr32.exe, which often indicates follow-on malicious activity such as command shell execution or lateral movement tools.
SentinelOne

