LOLBin Abuse: mshta Remote HTA, regsvr32 Squiblydoo, rundll32 Temp/AppData DLL
Detects potential defense evasion using common Windows LOLBins (Living off the Land Binaries) to execute code from untrusted locations or remote sources. Specifically targets mshta.exe loading remote HTA files, regsvr32.exe performing Squiblydoo-style COM scriptlet execution via URL, and rundll32.exe executing DLLs from user-writable directories like Temp or AppData.
SentinelOne

