Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0475 — Detection Strategy for T1218.011 Rundll32 Abuse
DET0475

Detection Strategy for T1218.011 Rundll32 Abuse

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1308 Analytic 1308
Windows

Detects rundll32.exe invoked with atypical arguments (.dll, .cpl, javascript:, mshtml). DLLs not normally loaded by rundll32 are mapped into memory. Control_RunDLL or RunHTMLApplication invoked. Suspicious DLLs or scripts accessed from disk or network. Rundll32 reaches out to external domains (e.g., fetching .sct or .hta).

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=3, 22
[TimeWindow] Correlating rundll32 invocation with DLL load or network activity within X seconds.
[ParentProcessFilter] Limit detection to suspicious parent processes (e.g., explorer.exe, office apps) vs. trusted installers.
[AllowedDLLs] Baseline list of legitimate DLLs frequently executed by rundll32 in the environment.
[ExternalIPRange] Scope of external IP ranges considered anomalous for rundll32 network connections.

Detected Techniques

1

Details

MITRE ID
DET0475
STIX ID
x-mitre-detection-strategy--a51d4d34-78fc-49b7-9071-348905dd33c2
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.