RunMRU Registry Value Containing rundll32/pcalua/powershell and @SSL
Detects the execution of suspicious commands via the Windows Explorer RunMRU registry key. RunMRU records commands previously entered in the 'Run' dialog box. Adversaries may use this mechanism to launch malicious scripts or tools (e.g., rundll32, powershell, pcalua) with potential arguments that include suspicious markers like '@ssl'. RunMRU registry values containing rundll32, pcalua, powershell, or @SSL, indicating a user-pasted Run command
Cortex XDR

