ClickOnce GapiUpdate chain: dfshim/dfsvc spawning Launcher/GapiUpdate.exe
Detects execution of potentially suspicious processes ('Launcher.exe' or 'GapiUpdate.exe') originating from ClickOnce-related processes ('dfsvc.exe' or 'rundll32.exe' with 'dfshim.dll'). ClickOnce is often abused to proxy execution of malicious code, allowing adversaries to execute applications from user-writable directories without administrative privileges.
Microsoft Sentinel (KQL)

