Most Popular Detection 2026: LOLBin Proxy Execution via Rundll32 and Regsvr32 (T1218.011, T1218.010)

Detects the abuse of Windows signed binaries (LOLBins) rundll32.exe and regsvr32.exe for proxy execution. Rundll32.exe activity is monitored for the use of javascript: pseudo-protocol or comsvcs.dll for MiniDump operations, while regsvr32.exe activity is monitored for Squiblydoo-style remote scriptlet execution via /i:http and other suspicious flag combinations.