Rundll32 LOLBin Abuse via MiniDump, url.dll, or JavaScript Protocol

Detects instances where rundll32.exe is executed with suspicious command-line parameters that are often associated with malicious activity. This includes attempts to dump memory (comsvcs.dll), utilize specific protocols (url.dll), execute JavaScript, or leverage common writeable directories for payload staging, all of which are common techniques used by attackers to proxy execution and evade defenses.