Invoke-Obfuscation Via Use Rundll32 - System
Description
Detects Obfuscated Powershell via use Rundll32 in Scripts
Query · sigma
selection: Provider_Name: Service Control Manager EventID: 7045 ImagePath|contains|all: - '&&' - rundll32 - shell32.dll - shellexec_rundll ImagePath|contains: - value - invoke - comspec - iex condition: selection
Known false positives
- Unknown