Windows Qakbot-associated Rundll32 execution via suspicious parent process and export strings

Flags rundll32.exe executions tied to Qakbot-style export strings when launched by script/cmd utilities.

FreeReviewedSigma · Critical · v5
Product
windows
Category
process_creation
Author
X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-24
Updated
2026-07-31

What it detects

This rule identifies Windows process creation where rundll32.exe is launched by specific scripting/command interpreters and the command line contains Qakbot-associated ProgramData/Public/AppData/Temp paths. It further matches command-line endings tied to a set of export identifiers commonly used in Qakbot execution flows. The detection relies on process creation telemetry including ParentImage, Image, and CommandLine to correlate the process tree and exported function string artifacts.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.