Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
Detects rundll32 executions that reference DLLs stored in Alternate Data Streams via ADS-style paths.
- Product
- windows
- Category
- process_creation
- Author
- Harjot Singh, '@cyb3rjy0t' (SigmaHQ), DRL 1.1
- Published
- 2023-01-21
- Updated
- 2026-07-30
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events where rundll32.exe is executed and the command line references a DLL located in an Alternate Data Stream (ADS) using a drive/path pattern with a colon separator. Attackers often use ADS to hide or store malicious payloads under legitimate-looking file paths, increasing stealth. Detection relies on Windows process creation telemetry, matching the Image/OriginalFileName for rundll32 and a command-line pattern consistent with an ADS path.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
id: 62bac228-1948-4faf-8a17-53409ee0442c
status: test
description: This rule flags process creation events where rundll32.exe is executed and the command line references a DLL located in an Alternate Data Stream (ADS) using a drive/path pattern with a colon separator. Attackers often use ADS to hide or store malicious payloads under legitimate-looking file paths, increasing stealth. Detection relies on Windows process creation telemetry, matching the Image/OriginalFileName for rundll32 and a command-line pattern consistent with an ADS path.
references:
- https://lolbas-project.github.io/lolbas/Binaries/Rundll32
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_ads_stored_dll_execution.yml
author: Harjot Singh, '@cyb3rjy0t', Huntrule Team
date: 2023-01-21
modified: 2026-03-16
tags:
- attack.stealth
- attack.t1564.004
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \rundll32.exe
- OriginalFileName: RUNDLL32.EXE
selection_cli:
CommandLine|re: "[Rr][Uu][Nn][Dd][Ll][Ll]32(?:\\.[Ee][Xx][Ee])? \\S+?\\w:\\S+?:"
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 9248c7e1-2bf3-4661-a22c-600a8040b446
type: derived