mshta.exe Blocked Bypass via RunHTMLApplication or Script Host HTA Load
Detects the use of legitimate Windows binaries (Rundll32, Wscript, Cscript, and Regsvr32) to execute scripts, HTML applications, or remote scriptlets. This pattern is commonly associated with adversary techniques to proxy execution of malicious code, bypass application controls, or retrieve payloads from remote servers.
Sigma

