LoFP LoFP / t1218.011

t1218.011

TitleTags
although unlikely, some legitimate applications may use a moved copy of rundll32, triggering a false positive.
although unlikely, some legitimate applications may use advpack.dll or ieadvpack.dll, triggering a false positive.
although unlikely, some legitimate applications may use setupapi triggering a false positive.
although unlikely, some legitimate applications may use start as a function and call it via the command line. filter as needed.
although unlikely, some legitimate applications may use syssetup.dll, triggering a false positive.
communication to other corporate systems that use ip addresses from public address spaces
false positives are possible with native utilities and third party applications. filtering may be needed based on command-line, or add world writeable paths to restrict query.
false positives depend on scripts and administrative tools used in the monitored environment
legitimate installation of a new screensaver
legitimate use of screen saver
limitted. this parameter is not commonly used by windows application but can be used by the network operator.
scripts and administrative tools that use inf files for driver installation with setupapi.dll
the installation of new screen savers by third party software
third party application may used this dll export name to execute function.
this is a hunting detection, meant to provide a understanding of how voluminous control_rundll is within the environment.
this is likely to produce false positives and will require some filtering. tune the query by adding command line paths to known good dlls, or filtering based on parent process names.
this may be tuned, or a new one related, by adding .cpl to command-line. however, it's important to look for both. tune/filter as needed.
unlikely
use of program compatibility troubleshooter helper
windows control panel elements have been identified as source (mmc)