
Summary
The 'Windows Rundll32 WebDAV Request' detection rule identifies the execution of 'rundll32.exe' with specific command-line arguments that relate to loading 'davclnt.dll' and the 'davsetcookie' function, which can be indicative of accessing a remote WebDAV instance. This analytic is particularly relevant due to its association with CVE-2023-23397, a vulnerability that could allow remote code execution or data exfiltration if exploited. The detection utilizes telemetry from Endpoint Detection and Response (EDR) systems, focusing on process and command-line data to flag potentially malicious activity. If rundll32.exe is invoked in this way, it could signal an attack, warranting immediate investigation.
Categories
- Endpoint
Data Sources
- Process
- Windows Registry
- Application Log
ATT&CK Techniques
- T1048.003
Created: 2024-11-13