Analytics BIOC Medium

Rundll32.exe running with no command-line arguments

Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Rundll32 (T1218.011)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:

Run as a signed Microsoft executables to avoid detection. Rundll32 is the default process used by Cobalt Strike for running post-exploitation tools.

Investigative actions:

Check for any injection event to the Rundll32 process. Check the causality of execution for any injections.

Test period:
N/A (single event)
Deduplication:
1 Day