RAT-spawned follow-on payload execution via rundll32/regsvr32/msiexec/script int
Detects instances where identified RAT-associated or potentially malicious parent processes spawn command-line interpreters (e.g., cmd, powershell) or execute archive management commands, which is indicative of secondary stage payload deployment or automated execution following initial compromise.
Sigma

