XHOPELESS Indirect Execution via mshta, wmic, or rundll32 ShellExec_RunDLL

Detects the use of living-off-the-land binaries such as mshta.exe, wmic.exe, and rundll32.exe to execute commands or code indirectly. This technique is often used to bypass security restrictions that might prevent the direct execution of common command-line interpreters.