InstallUtil.exe LOLBin Proxy Execution via Suspicious Flags or Child Processes
This rule detects potential misuse of the legitimate Windows utility 'InstallUtil.exe' for proxy execution. It flags instances where InstallUtil is executed with suspicious command-line parameters often used for bypass techniques (e.g., logging flags or loading code from user-writable directories like Temp, AppData, or Downloads), or when InstallUtil acts as a parent process to suspicious child processes typically associated with post-exploitation activities.
SentinelOne

