T1218 – System Binary Proxy Execution (CrowdStrike Detection)
CrowdStrike Alert Details Alert ID: CS-RUNDLL32-1218-7842 Alert Time: 2024-02-20 11:30:22 EST Severity: HIGH (88/100) Source: CrowdStrike Falcon EDR Rule: “Suspicious Rundll32 Execution – No Command Line Arguments” MITRE ATT&CK: T1218.011 – System Binary Proxy Execution: Rundll32 Alert Details: Detection: Rundll32.exe executed with suspicious parameters Host: MKT-WS-078 (Marketing Department) User: sjones (Sarah Jones, Marketing Manager) Time: … Read more