Obfuscated PowerShell Persistence (COLDRIVER / MAYBEROBOT)
This rule detects suspicious execution of 'RUNDLL32.EXE' with specific command-line arguments. It looks for instances where 'RUNDLL32.EXE' is executed with both a backslash and a comma in the command line, combined with specific DLL names or keywords like 'iamnotarobot.dll', 'checkme.dll', 'machinerie.dll', 'humanCheck', or 'verifyme'. This pattern is often indicative of malicious DLL loading or persistence mechanisms.
Microsoft Sentinel (KQL)

