Invoke-Obfuscation Via Use Rundll32 - Security — Detection Rule

Detects Obfuscated Powershell via use Rundll32 in Scripts

Read the full analysis on IntelFusions