Potential Rundll32 Execution With DLL Stored In ADS

 Original Source: [Sigma source]
Title: Potential Rundll32 Execution With DLL Stored In ADS
Status: test
Description:Detects execution of rundll32 where the DLL being called is stored in an Alternate Data Stream (ADS).
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Rundll32
Author: Harjot Singh, '@cyb3rjy0t'
Date: 2023-01-21
modified:2026-03-16
Tags:
  • -'attack.stealth'
  • -'attack.t1564.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\rundll32.exe' OriginalFileName:'RUNDLL32.EXE'   selection_cli:
    CommandLine|re: '[Rr][Uu][Nn][Dd][Ll][Ll]32(?:\.[Ee][Xx][Ee])? \S+?\w:\S+?:'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high