Most Important LOLBAS Detection 2026: Cmstp.exe UAC Bypass via Malicious INF Exe

Detects execution of the Microsoft Connection Manager Profile Installer (cmstp.exe) with suspicious command-line parameters (using remote INF files via UNC or HTTP) or when it spawns unexpected child processes, both of which are indicative of potential bypass of User Account Control (UAC) or security controls.