LoFP LoFP / t1218.011

t1218.011

TitleTags
a certain amount of false positives are likely with this detection. msi based installers often trigger for setupapl.dll and vendors will often copy system exectables to a different path for application usage.
although unlikely, some legitimate applications may leverage one of the following dlls syssetup.dll, dvpack.dll, ieadvpack.dll and can trigger a false positive. apply additional filters as needed.
although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive.
although unlikely, some legitimate applications may use start as a function and call it via the command line. filter as needed.
communication to other corporate systems that use ip addresses from public address spaces
false positives are possible with native utilities and third party applications. filtering may be needed based on command-line, or add world writeable paths to restrict query.
false positives depend on scripts and administrative tools used in the monitored environment
legitimate installation of a new screensaver
legitimate use of screen saver
limitted. this parameter is not commonly used by windows application but can be used by the network operator.
no false positives have been identified at this time.
scripts and administrative tools that use inf files for driver installation with setupapi.dll
the installation of new screen savers by third party software
third party application may used this dll export name to execute function.
this is a hunting detection, meant to provide a understanding of how voluminous control_rundll is within the environment.
this is likely to produce false positives and will require some filtering. tune the query by adding command line paths to known good dlls, or filtering based on parent process names.
this may be tuned, or a new one related, by adding .cpl to command-line. however, it's important to look for both. tune/filter as needed.
udl files serve as a convenient and flexible tool for managing and testing database connections in various development and administrative scenarios.
unknown
unlikely
use of program compatibility troubleshooter helper
vendors, third party software or update processes may use versions of the binaries listed in the lookup table from non-standard paths. it is recommended to tune this analytic to exclude any known legitimate software or paths in your environment