Most Popular LOLBAS 2026: Rundll32 Executing DLL from Suspicious Non-Standard Di
Detects instances of rundll32.exe being executed with command line arguments that point to DLLs in common user-writable or non-standard directories (e.g., Temp, AppData, Downloads, ProgramData) or employing known malicious command patterns like Control_RunDLL, javascript: protocol handlers, or shell32.dll proxy execution techniques often used to evade security controls.
Sigma

