ByteRay CQL Hub
← All queries

LOLBin Rundll32

This query detects the use of Rundll32 from parents that are known for misuse.

CQL · Falcon Next-Gen SIEMCopy query
in(#event_simpleName, values=["ProcessRollup2","ProcessBlocked"])
| event_platform=Win and ImageFileName=/rundll32.exe/i
| in(ParentBaseFileName, values=["cmd.exe","winword.exe","powerpnt.exe","excel.exe","outlook.exe","mshta.exe","cscript.exe","wscript.exe"])

Rundll32.exe – A native Windows binary that can be abused to execute DLLs, scripts, and other payloads, making it a common technique in Living-off-the-Land attacks.

LOLBAS - Rundll32.exe

LOLBin_Rundll32.yml
T1218.011, T1564.004
ByteRay GmbH
Hunting
Endpoint
Insight
2025-08-06
2025-08-26

Get this query running in your SIEM, with someone on call.

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team