Windows rundll32.exe execution with no parameters or arguments

Alerts on Windows rundll32.exe being started with an empty/no-parameter command line.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Bartlomiej Czyz, Relativity (SigmaHQ), DRL 1.1
Published
2021-01-31
Updated
2026-07-30

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creation events where rundll32.exe is launched with no command-line parameters or arguments beyond the executable name. Attackers may use rundll32 to execute functionality indirectly while keeping the command line minimal, so the absence of parameters can be a useful anomaly indicator. Telemetry required is Windows process creation with access to the full CommandLine field.

Related detections9 linkedT1021.002 — drag to rearrange
Windows Service Installation (EID 4697) for SMB PsExec by Metasploit or Impacket
Suspicious Ransomware Fan-Out Deployment via PsExec Spread (Qilin)
Malicious Remote Process Execution From an SMB Admin Share (via process_creation)
Malicious PsExec Service Installation via PSEXESVC
Suspicious Lateral Movement via PsExec Service (via process_creation)
Possible PsExec Remote Service Installation with Randomly Named Service (via security)
Suspicious PsExec Copying Payload To Windows Temp (via process_creation)
Windows Named Pipe Creation: Default RemCom Pipe Name
Windows Named Pipe Created for CSExec Default Pipe Name
Windows rundll32.exe execution with no parameters or arguments
Pivot detection · T1021.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.