LOLBin Proxy Execution with URL/Script Args or Network Egress
Detects the execution of known Living-off-the-Land Binaries (LOLBins) such as mshta, certutil, regsvr32, rundll32, and msiexec, where the command-line arguments contain suspicious patterns indicative of script execution or remote file fetching. These behaviors are consistent with T1218 (System Binary Proxy Execution) to bypass security controls by utilizing trusted, signed binaries to execute malicious code.
YARA-L

