flâneur — a map of the web's best reading

DLLHost with no Command Line Arguments with Network - Splunk Security Content

research.splunk.com · 777 words · saved by 1 readers

This detection has been marked experimental by the Splunk Threat Research team. This means we have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is NOT supported. Try in Splunk Security Cloud The following analytic identifies DLLHost.exe with no command line arguments with a network connection. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, triage any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. The SPL above uses the following Macros: dllhost_with_no_command_line_arguments_with_network_filter is a empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL. List of fields requir

Detection: DLLHost with no Command Line Arguments with Network | Splunk Security Content Table of Contents Detection: DLLHost with no Command Line Arguments with Network Updated Date: 2026-05-13 ID: f1c07594-a141-11eb-8407-acde48001122 Author: Steven Dick, Michael Haag, Splunk Type: TTP Product: Splunk Enterprise Security Description The following analytic detects instances of DLLHost.exe running without command line arguments while establishing a network connection. This behavior is identified using Endpoint Detection and Response (EDR) telemetry, focusing on process execution and network act

Explore this link on the map →

related reading