Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32

Alerts on suspicious Windows process launches of key binaries with missing/empty arguments, excluding common Edge/Chromium installer use.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2020-10-23
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags Windows process executions where the Image and CommandLine end with specific binaries (rundll32.exe, WerFault.exe, regsvcs.exe, regasm.exe, or regsvr32.exe) without including additional command-line arguments. Attackers may rely on these “default” or improperly handled invocations as sacrificial processes to carry out capability injection or other stealthy actions without conforming to normal execution patterns. The detection relies on process creation telemetry that captures the executable path and full command line, with exclusions for certain EdgeUpdate/Chromium uninstall-related rundll32.exe activity.

Related detections9 linkedT1218.011 — drag to rearrange
Malicious DLL Execution With Non Standard Extension via rundll32
Andromeda Loader Execution via Rundll32 Desktop.ini Ordinal
Suspicious rundll32 Execution of sqlite3 DLL by Ordinal with TLB Argument
Malicious Zardoor Backdoor Execution via rundll32 (via process_creation)
Malicious Rundll32 Loading an Export From a User Path (via process_creation)
Renamed Regsvr32 or Rundll32 Loading a DLL With a Non-Standard Extension (via process_creation)
Malicious Rundll32 DllRegisterServer Execution From a User-Writable Path (via process_creation)
IMEEX Framework DLL Execution via Rundll32 Loading imaadp (via process_creation)
Suspicious Persistence via pcalua Launching rundll32 Control_RunDLL
Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32
Pivot detection · T1218.011 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.