Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

← Amenazas
Técnica MITRE ATT&CK · stealth

T1218.011 Rundll32

Subtécnica de T1218 System Binary Proxy Execution

Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. [Shared Modules](https://attack.mitre.org/techniques/T1129)), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing…

Ficha en MITRE ATT&CK ↗

Quién la usa · con noticias en Jábega

Reglas Sigma para cazarla

Mostrando 25 de 40.

Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.