實測 Windows 內建 rundll32.exe 的三大濫用手法:透過 mshtml 執行 JavaScript、以 shell32/advpack/pcwutl 代理執行指令,以及對應的偵測與 AppLocker、Sysmon 防禦設定。
Topic: #Rundll32
A collection of 1 post about Rundll32.
A collection of 1 post about Rundll32.
實測 Windows 內建 rundll32.exe 的三大濫用手法:透過 mshtml 執行 JavaScript、以 shell32/advpack/pcwutl 代理執行指令,以及對應的偵測與 AppLocker、Sysmon 防禦設定。