T1218.011 Rundll32
Sub-technique of T1218 System Binary Proxy Execution
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. [Shared Modules](https://attack.mitre.org/techniques/T1129)), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- APT29 2018 Phishing Campaign CommandLine Indicatorscriticalstable · windows
- APT29 2018 Phishing Campaign File Indicatorscriticalstable · windows
- Equation Group DLL_U Export Function Loadcriticalstable · windows
- EvilNum APT Golden Chickens Deployment Via OCX Filescriticaltest · windows
- HackTool - F-Secure C3 Load by Rundll32criticaltest · windows
- NotPetya Ransomware Activitycriticaltest · windows
- Potential Emotet Rundll32 Executioncriticaltest · windows
- ZxShell Malwarecriticaltest · windows
- Bad Opsec Defaults Sacrificial Processes With Improper Argumentshightest · windows
- CobaltStrike Load by Rundll32hightest · windows
- Fireball Archer Installhightest · windows
- HTML Help HH.EXE Suspicious Child Processhightest · windows
- HackTool - RedMimicry Winnti Playbook Executionhightest · windows
- IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32hightest · windows
- Kapeka Backdoor Execution Via RunDLL32.EXEhightest · windows
- Kapeka Backdoor Loaded Via Rundll32.EXEhightest · windows
- Potential Bumblebee Remote Thread Creationhightest · windows
- Potential PowerShell Execution Via DLLhightest · windows
- Potential Raspberry Robin CPL Execution Activityhightest · windows
- Process Access via TrolleyExpress Exclusionhightest · windows
- RunDLL32 Spawning Explorerhightest · windows
- Rundll32 UNC Path Executionhightest · windows
- Shell32 DLL Execution in Suspicious Directoryhightest · windows
- Sofacy Trojan Loader Activityhightest · windows
- Suspicious Control Panel DLL Loadhightest · windows
Showing 25 of 40.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.