LOLBin Rundll32
This query detects the use of Rundll32 from parents that are known for misuse.
CQL · Falcon Next-Gen SIEMCopy query
in(#event_simpleName, values=["ProcessRollup2","ProcessBlocked"])
| event_platform=Win and ImageFileName=/rundll32.exe/i
| in(ParentBaseFileName, values=["cmd.exe","winword.exe","powerpnt.exe","excel.exe","outlook.exe","mshta.exe","cscript.exe","wscript.exe"])Rundll32.exe – A native Windows binary that can be abused to execute DLLs, scripts, and other payloads, making it a common technique in Living-off-the-Land attacks.
LOLBin_Rundll32.yml
T1218.011, T1564.004
ByteRay GmbH
Hunting
Endpoint
Insight
2025-08-06
2025-08-26
