Security researchers documented and detection engineers tracked a Windows application control bypass technique in which rundll32.exe invokes the LaunchINFSection function in advpack.dll, ieadvpack.dll, or syssetup.dll to execute script content from INF files. The behavior is associated with LOLBAS tradecraft and can be abused to bypass allowlisting controls, enabling arbitrary code execution and creating opportunities for privilege escalation, persistence, and wider host compromise.
Splunk published analytics to identify this activity using EDR and Windows process telemetry, including command-line logging, Sysmon Event ID 1, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data mapped to the Endpoint data model. Those detections, aligned to MITRE ATT&CK T1218.011 for Rundll32, were later deprecated and replaced by a broader rule named "Windows Application Whitelisting Bypass Attempt via Rundll32," while the underlying technique remained notable because legitimate use of these DLL invocation patterns is considered uncommon and potentially high-signal for malicious execution.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detections "Detect Rundll32 Application Control Bypass - advpack" and "Detect Rundll32 Application Control Bypass - syssetup" from its content library after deprecating them. Both were replaced by a newer detection named "Windows Application Whitelisting Bypass Attempt via Rundll32."
The LOLBAS Project published an entry for Advpack, documenting it as a living-off-the-land binary/script/library technique reference.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourcelolbas-project.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.