Rundll32 Executing DLL From Remote Network Share
Detects rundll32.exe loading content directly from a UNC path. This behavior is rare in enterprise environments and was observed in ACR Stealer delivery chains.
Microsoft Sentinel (KQL)

Detects rundll32.exe loading content directly from a UNC path. This behavior is rare in enterprise environments and was observed in ACR Stealer delivery chains.

Already have an account?