Techniques
Sample rules
Rundll32 Execution Without Parameters
- source: sigma
- technicques:
- t1021
- t1021.002
- t1569
- t1569.002
- t1570
Description
Detects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module
Detection logic
condition: selection
selection:
CommandLine:
- rundll32.exe
- rundll32