Windows: Rundll32 Executions Using Obfuscated Ordinal Call Arguments

Flags rundll32.exe launches with command-line ordinal obfuscation patterns.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-17
Updated
2026-07-30

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process creation events where rundll32.exe is executed and the command line includes obfuscation patterns consistent with ordinal-based calls. Obfuscated ordinal arguments can help an attacker evade simple string-based detections while still invoking specific exports. It relies on Windows process creation telemetry, including the executable name and the full command line content.

Related detections9 linkedT1027.010 — drag to rearrange
PowerShell Command-Line Obfuscation Constructs (via process_creation)
Windows Process Creation: Python One-Liners Decoding Base64 via Command Line
Linux Process Execution of Python Base64 Decode One-Liners
Windows CMD for /f Tokens= with Recursive Dir Listing
Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Windows Registry: Suspicious Space-Padded TypedPaths Details String
Windows PowerShell Obfuscated COM MSI Installation via WindowsInstaller.Installer
Windows Registry Set in Shell Open Command Using PowerShell Cryptography .NET Classes
Windows: Rundll32 Executions Using Obfuscated Ordinal Call Arguments
Pivot detection · T1027.010 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.