InstallUtil.exe LOLBin Proxy Execution via Suspicious Flags or Child Processes
This rule detects potential misuse of the legitimate Windows utility InstallUtil.exe (a .NET component installer) to proxy the execution of malicious code. It identifies two specific suspicious patterns: first, the execution of InstallUtil with command-line arguments indicative of bypass attempts (e.g., /logfile, /LogToConsole, or /U) or loading files from user-writable directories (Temp, AppData, Downloads, ProgramData); second, instances where InstallUtil spawns potentially malicious child processes such as PowerShell, cmd, or various system binaries often used for persistence or lateral movement.
SentinelOne

