Windows Process Creation: rundll32 Spawns Pikabot-Like Hollowing Binaries

Alerts when rundll32.exe spawns specific Windows binaries in patterns consistent with potential process hollowing.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Andreas Braathen (mnemonic.io) (SigmaHQ), DRL 1.1
Published
2023-10-27
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process executions where rundll32.exe spawns specific legitimate Windows binaries associated with process hollowing behavior. An attacker can use this technique to start benign processes while replacing their contents to evade detection and complicate analysis. It relies on process creation telemetry capturing parent Image and command line, along with child process Image paths. The rule also filters a known benign case involving rundll32 launching sndvol.exe via the mmsys.cpl context.

Related detections9 linkedT1055.012 — drag to rearrange
Suspicious Execution of Dotnet Injection Target Utilities
Suspicious AppLaunch.exe Spawned As Injection Target (via process_creation)
Suspicious JScript.NET Compiler Spawned by AutoIt for Process Hollowing
PureHVNC Process Hollowing into RegAsm Spawned by PowerShell (via process_creation)
Suspicious DotNet Utility Spawned by Script Host for Hollowing (via process_creation)
Suspicious RegSvcs Reflective .NET Load from Fake Update Chain
In-Memory XWorm Injection Target RegAsm Spawned from User AppData (via process_creation)
Possible Process Injection Target RegAsm Launched Without Arguments via Process Creation
In-Memory Regasm Process Hollowing Spawned by PowerShell (via process_creation)
Windows Process Creation: rundll32 Spawns Pikabot-Like Hollowing Binaries
Pivot detection · T1055.012 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.