Rundll32 Execution Without CommandLine Parameters

 Original Source: [Sigma source]
Title: Rundll32 Execution Without CommandLine Parameters
Status: test
Description:Detects suspicious start of rundll32.exe without any parameters as found in CobaltStrike beacon activity
References:
  -https://www.cobaltstrike.com/help-opsec
  -https://twitter.com/ber_m1ng/status/1397948048135778309
Author: Florian Roth (Nextron Systems)
Date: 2021-05-27
modified:2023-08-31
Tags:
  • -'attack.stealth'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|endswith:
      -'\rundll32.exe'
      -'\rundll32.exe"'
      -'\rundll32'

  filter:
    ParentImage|contains:
      -'\AppData\Local\'
      -'\Microsoft\Edge\'

  condition:selection and not filter
Falsepositives:
  -Possible but rare
Level: high