Suspicious Rundll32 Execution Without Arguments

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-10-04
Updated
2026-10-04

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects rundll32.exe launched with no DLL or export arguments, a hollowing or injection precursor observed in the Gootloader chain. A bare rundll32 process is typically spawned to host injected code rather than to run a legitimate library export. This anomaly is a reliable indicator of process injection staging.

Related detections9 linkedT1055 — drag to rearrange
In-Memory Rundll32 Execution Without a Command Line (via process_creation)
Malicious rundll32 Execution of BoomBox NativeCache DLL (via process_creation)
Malicious rundll32 vbscript mshtml RunHTMLApplication Execution
Malicious Quantum Ransomware ttsel Payload Execution via Command Line
Malicious rundll32 WebDAV UNC Execution over HTTP
Malicious PowerShell Runtime Loaded Outside PowerShell Host
Suspicious rundll32 Execution of DLL from WebDAV Share (via process_creation)
Suspicious App Domain Manager Injection via Environment Variables
Suspicious Svchost Execution from Non-Services Parent
Suspicious Rundll32 Execution Without Arguments
Pivot detection · T1055 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.