Windows rundll32.exe executing InstallScreenSaver via desk.cpl SCR File
Detects rundll32.exe launches with InstallScreenSaver behavior via desk.cpl, a screensaver execution technique.
- Product
- windows
- Category
- process_creation
- Author
- Christopher Peacock @securepeacock, SCYTHE @scythe_io, TactiKoolSec (SigmaHQ), DRL 1.1
- Published
- 2022-04-28
- Updated
- 2026-07-30
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation where rundll32.exe is invoked with a command line containing InstallScreenSaver, consistent with launching a screensaver (desk.cpl) execution path. Attackers use this technique to blend execution into normal-looking desktop component activity while loading functionality through rundll32. It relies on Windows process creation telemetry, specifically the executable image/original filename and the command line content.
Reporting behind it
- lolbas-project.github.iohttps://lolbas-project.github.io/lolbas/Libraries/Desk/
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1218.011/T1218.011.md#atomic-test-13---rundll32-with-deskcpl
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_installscreensaver.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows rundll32.exe executing InstallScreenSaver via desk.cpl SCR File
id: 92a68cb3-2d7b-47a5-b64c-c051efce1865
status: test
description: This rule flags process creation where rundll32.exe is invoked with a command line containing InstallScreenSaver, consistent with launching a screensaver (desk.cpl) execution path. Attackers use this technique to blend execution into normal-looking desktop component activity while loading functionality through rundll32. It relies on Windows process creation telemetry, specifically the executable image/original filename and the command line content.
references:
- https://lolbas-project.github.io/lolbas/Libraries/Desk/
- https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1218.011/T1218.011.md#atomic-test-13---rundll32-with-deskcpl
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_installscreensaver.yml
author: Christopher Peacock @securepeacock, SCYTHE @scythe_io, TactiKoolSec, Huntrule Team
date: 2022-04-28
modified: 2023-02-09
tags:
- attack.stealth
- attack.t1218.011
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \rundll32.exe
- OriginalFileName: RUNDLL32.EXE
selection_cli:
CommandLine|contains: InstallScreenSaver
condition: all of selection_*
falsepositives:
- Legitimate installation of a new screensaver
level: medium
license: DRL-1.1
related:
- id: 15bd98ea-55f4-4d37-b09a-e7caa0fa2221
type: derived