LOLBin Proxy Execution via Rundll32/Regsvr32

Detects execution of rundll32.exe or regsvr32.exe with potentially malicious command-line arguments, including references to external URLs, protocol handlers like javascript:, or loading DLLs from user-writable directories (Temp, AppData, Downloads). This behavior is characteristic of Living-off-the-Land (LotL) techniques used to proxy execution and bypass application control or security monitoring.