Code Execution via Pcwutl.dll
Description
Detects launch of executable by calling the LaunchApplication function from pcwutl.dll library.
Query · sigma
selection_img: - Image|endswith: \rundll32.exe - OriginalFileName: RUNDLL32.EXE selection_cli: CommandLine|contains|all: - pcwutl - LaunchApplication condition: all of selection_*
Known false positives
- Use of Program Compatibility Troubleshooter Helper