AdaptixC2 - Rundll32 Reflective DLL Injection for C2 Agent Deployment
Detects the deployment of AdaptixC2 agents by monitoring for suspicious rundll32.exe process executions indicative of reflective DLL injection. This includes rundll32.exe loading DLLs from suspicious directories (Temp, AppData, ProgramData) with potential reflective loader flags or exported functions, often triggered by parent processes like msiexec.exe or consent.exe. The rule also monitors for direct outbound network connections from rundll32.exe to known AdaptixC2 command-and-control infrastructure.
SentinelOne

