Tag
low
advisory
Command Shell Activity Started via RunDLL32
2 rules 4 TTPsThis rule detects command shell activity, such as cmd.exe or powershell.exe, initiated by RunDLL32, a technique commonly abused by attackers to execute malicious code and bypass security controls.
M365 Defender +2
execution
command-shell
rundll32
2r
4t
high
advisory
Suspicious Windows Command Shell Arguments
2 rules 5 TTPsThis rule identifies suspicious uses of the Windows Command Shell (cmd.exe) with unusual command-line arguments often associated with malware installation, script execution, or system manipulation.
Windows
execution
command-shell
2r
5t
low
advisory
Command Shell Activity Started via RunDLL32
2 rules 5 TTPsAdversaries abuse RunDLL32, a legitimate Windows utility, to execute command shells (cmd.exe or PowerShell) for malicious purposes, bypassing security controls.
Windows
rundll32
command-shell
proxy-execution
2r
5t