Addinutil.exe Suspicious Execution
This rule detects suspicious execution patterns of addinutil.exe, a legitimate .NET utility that can be abused for arbitrary code execution. It specifically looks for two conditions: 1) addinutil.exe being executed from its standard .NET Framework directories with the '-AddinRoot .' argument, which is a known LOLBAS technique to load a payload from the current directory, and 2) addinutil.exe being executed from an uncommon or non-standard directory, which could indicate an adversary has copied the utility to a different location for malicious purposes.
Microsoft Sentinel (KQL)

