MMC.exe LOLBin Abuse - Suspicious .msc Load or Child Process Spawn (T1218.014)
This rule monitors for potential abuse of the Microsoft Management Console (mmc.exe) to proxy malicious activity. It detects three primary behaviors: 1) mmc.exe being launched with a .msc file originating from user-writable or suspicious directories; 2) mmc.exe spawning known suspicious child processes (e.g., powershell.exe, cmd.exe, rundll32.exe); and 3) the creation or modification of .msc files in suspicious locations by processes other than mmc.exe or msiexec.exe.
SentinelOne

