
Rule Info
Tags
attack.defense_evasion DEMO
Name
Potential Obfuscated Ordinal Call Via Rundll32
Id
43fa5350-db63-4b8f-9a01-789a427074e1
Date
2023-05-17 00:00:00
Modified
None
Description
Detects execution of "rundll32" with potential obfuscated ordinal calls
Reference
Internal Research
Author
Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule
Link to Public Repo
Rule History
Title
Author
Commit
Date