LOLBin process loading WMI COM DLLs (wbemcomn/wbemprox)
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
Microsoft Sentinel (KQL)

