1200KM / detection
T1218.011 Rundll32 — Detection Rules
Detection workspace for T1218.011 Rundll32: 27 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remote Thread Creation Via PowerShell In Uncommon Target · test · medium · {"product":"windows","category":"create_remote_thread"}
- SCR File Write Event · test · medium · {"category":"file_event","product":"windows"}
- Unsigned DLL Loaded by Windows Utility · test · medium · {"product":"windows","category":"image_load"}
- Rundll32 Internet Connection · test · medium · {"category":"network_connection","product":"windows"}
- Outbound Network Connection To Public IP Via Winlogon · test · medium · {"category":"network_connection","product":"windows"}
- Process Access via TrolleyExpress Exclusion · test · high · {"category":"process_creation","product":"windows"}
- HTML Help HH.EXE Suspicious Child Process · test · high · {"category":"process_creation","product":"windows"}
- Suspicious HH.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - F-Secure C3 Load by Rundll32 · test · critical · {"category":"process_creation","product":"windows"}
- CobaltStrike Load by Rundll32 · test · high · {"category":"process_creation","product":"windows"}
- HackTool - RedMimicry Winnti Playbook Execution · test · high · {"product":"windows","category":"process_creation"}
- Code Execution via Pcwutl.dll · test · medium · {"category":"process_creation","product":"windows"}
- Rundll32 InstallScreenSaver Execution · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Rundll32 Setupapi.dll Activity · test · medium · {"category":"process_creation","product":"windows"}
- Shell32 DLL Execution in Suspicious Directory · test · high · {"category":"process_creation","product":"windows"}
- RunDLL32 Spawning Explorer · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Rundll32 Activity · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Control Panel DLL Load · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Rundll32 Execution With Image Extension · test · high · {"category":"process_creation","product":"windows"}
- Suspicious ShellExec_RunDLL Call Via Ordinal · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Rundll32 Activity Invoking Sys File · test · high · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Rundll32.EXE Execution of UDL File · test · medium · {"category":"process_creation","product":"windows"}
- Rundll32 UNC Path Execution · test · high · {"category":"process_creation","product":"windows"}
- Rundll32 Execution With Uncommon DLL Extension · test · medium · {"category":"process_creation","product":"windows"}
- Bad Opsec Defaults Sacrificial Processes With Improper Arguments · test · high · {"category":"process_creation","product":"windows"}
- Potential PowerShell Execution Via DLL · test · high · {"category":"process_creation","product":"windows"}
- ScreenSaver Registry Key Set · test · medium · {"product":"windows","category":"registry_set"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0475 Detection Strategy for T1218.011 Rundll32 Abuse
AN1308 Analytic 1308
Detects rundll32.exe invoked with atypical arguments (.dll, .cpl, javascript:, mshtml). DLLs not normally loaded by rundll32 are mapped into memory. Control_RunDLL or RunHTMLApplication invoked. Suspicious DLLs or scripts accessed from disk or network. Rundll32 reaches out to external domains (e.g., fetching .sct or .hta).
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Carbanak · G0008
- APT3 · G0022
- Lazarus Group · G0032
- Sandworm Team · G0034
- FIN7 · G0046
- Gamaredon Group · G0047
- APT32 · G0050
- CopyKittens · G0052
- Magic Hound · G0059
- MuddyWater · G0069
- APT19 · G0073
- APT38 · G0082
- TA505 · G0092
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- HAFNIUM · G0125
- TA551 · G0127
- LazyScripter · G0140
- Aquatic Panda · G0143
- Daggerfly · G1034
- RedCurl · G1039
- UNC3886 · G1048
- Storm-0501 · G1053
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.