Rundll32 Execution Without Parameters — Detection Rule

Detects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module

Read the full analysis on IntelFusions