Most Popular Detection 2026: LOLBin Abuse via Rundll32 and Regsvr32 for Defense Evasion

This rule detects the suspicious execution of rundll32.exe or regsvr32.exe, which are commonly abused as Living-off-the-Land Binaries (LOLBins). It identifies potential malicious activity by analyzing command-line arguments for patterns like remote URL requests, usage of scrobj.dll, JavaScript protocols, or specific Squiblydoo attack patterns. Additionally, it monitors for these binaries being executed by parents other than explorer.exe, which is indicative of potential process injection or proxy execution.