(SourceImage:\\powershell.exe OR SourceImage:\\pwsh.exe) (TargetImage:\\rundll32.exe OR TargetImage:\\regsvr32.exe)