This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Rundll32 Execution Without CommandLine Parameters
Original Source:
[Sigma source]
Title:
Rundll32 Execution Without CommandLine Parameters
Status:
test
Description:
Detects suspicious start of rundll32.exe without any parameters as found in CobaltStrike beacon activity
References:
-https://www.cobaltstrike.com/help-opsec
-https://twitter.com/ber_m1ng/status/1397948048135778309
Author:
Florian Roth (Nextron Systems)
Date:
2021-05-27
modified:
2023-08-31
Tags:
-'attack.stealth'
-'attack.t1202'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|endswith
:
-'\rundll32.exe'
-'\rundll32.exe"'
-'\rundll32'
filter:
ParentImage|contains
:
-'\AppData\Local\'
-'\Microsoft\Edge\'
condition
:
selection and not filter
Falsepositives:
-Possible but rare
Level:
high