Windows rundll32 WebDAV Client Execution (davclnt.dll DavSetCookie)

Flags svchost.exe spawning rundll32.exe to run davclnt.dll,DavSetCookie, consistent with WebDAV client execution.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
Published
2020-05-02
Updated
2026-07-30

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule identifies svchost.exe spawning rundll32.exe with a command line containing the WebDAV client library function DavSetCookie from davclnt.dll. Such execution can indicate automated WebDAV access that may be leveraged to facilitate data movement or launch behaviors via a remote WebDAV context. It relies on Windows process creation telemetry, including the parent/child image paths and the rundll32 command line content.

Related detections9 linkedT1048.003 — drag to rearrange
FTP Data Exfiltration via curl with Embedded Credentials
Suspicious Data Exfiltration via TFTP Client
Suspicious Finger Client Execution for Command and Control
Malicious dnscat2 DNS Tunneling C2 Traffic
Suspicious Data Transfer via curl to Raw IP Address
Linux Python CLI Web Server Execution via http.server or SimpleHTTPServer
Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
PowerShell Script Exfiltration Attempt: Send-MailMessage with Attachments
Windows Suspicious Outbound SMTP Connections on Common Mail Ports
Windows rundll32 WebDAV Client Execution (davclnt.dll DavSetCookie)
Pivot detection · T1048.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.