Regsvr32.exe Squiblydoo Execution
Detects the use of regsvr32.exe to execute a remote scriptlet (.sct file) via a URL, a technique often referred to as 'Squiblydoo'. This method bypasses application control by leveraging a trusted Microsoft binary to proxy execution of malicious code.
SentinelOne

