LOLBAS shell32

This rule detects the execution of `rundll32.exe` with `shell32.dll` that subsequently launches `cmd.exe`. This behavior is often associated with adversaries using `rundll32.exe` as a proxy to execute commands, specifically leveraging `shell32.dll` to invoke `cmd.exe`. The rule includes several exclusions to reduce false positives, such as legitimate `msiexec.exe` parent processes, specific `RunDLL` commands, and `autorun.bat` related activities.