Rundll32 execution of DLL payload staged via WebDAV path

Detects the execution of rundll32.exe with a command line containing 'DavWWWRoot', indicating the loading of a DLL from a remote WebDAV share. This is a common technique used by attackers to execute remote malicious code while bypassing local execution policies or attempting to evade local file-based detection.