Rundll32 Execution Without Parameters

 Original Source: [Sigma source]
Title: Rundll32 Execution Without Parameters
Status: test
Description:Detects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module
References:
  -https://bczyz1.github.io/2021/01/30/psexec.html
Author: Bartlomiej Czyz, Relativity
Date: 2021-01-31
modified:2023-02-28
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
  • -'attack.t1570'
  • -'attack.execution'
  • -'attack.t1569.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine:
      -'rundll32.exe'
      -'rundll32'

  condition:selection
Falsepositives:
  -False positives may occur if a user called rundll32 from CLI with no options
Level: high