Potential LethalHTA Technique Execution — Detection Rule

Detects potential LethalHTA technique where the "mshta.exe" is spawned by an "svchost.exe" process

Read the full analysis on IntelFusions