Suspicious WebDav Client Execution Via Rundll32.EXE (982e9f2d-1a85-4d5b-aea4-31f5e97c6555)
Detects "svchost.exe" spawning "rundll32.exe" with command arguments like C:\windows\system32\davclnt.dll,DavSetCookie. This could be an indicator of exfiltration or use of WebDav to launch code (hosted on WebDav Server) or potentially a sign of exploitation of CVE-2023-23397