LoFP LoFP / legitimate installation of a new screensaver

Techniques

Sample rules

Rundll32 InstallScreenSaver Execution

Description

An attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver

Detection logic

condition: all of selection_*
selection_cli:
  CommandLine|contains: InstallScreenSaver
selection_img:
- Image|endswith: \rundll32.exe
- OriginalFileName: RUNDLL32.EXE