Regsvr32 Squiblydoo AppLocker Bypass (T1218.010)

Detects execution of regsvr32.exe with command-line arguments that include a remote URL ('/i:http...') combined with silent, unregistered, and notification-free execution flags ('/s', '/u', '/n'). This behavior is characteristic of the 'Squiblydoo' technique, where attackers use Regsvr32 to execute arbitrary scriptlets from remote servers to bypass application whitelisting.