BIOC Medium

Rundll32.exe with 'main' as EntryPoint

Rundll32.exe ran with 'main' as EntryPoint. Attackers may leverage rundll32.exe to execute malicious functions and DLLs.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Execution
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution: Rundll32 (T1218.011)
Indicator:

Process action type = execution AND target process cmd =~ rundll32.*dll[\s]*,[\s]*main

Preventable: yes