Invoke-Obfuscation Via Use Rundll32 - System — Detection Rule

Detects Obfuscated Powershell via use Rundll32 in Scripts

Read the full analysis on IntelFusions