Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
144 rules
PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh297Free2019-10-08Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
juju4, Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium155Free2019-01-16Windows: NotPetya indicators via wevtutil log clearing, fsutil deletejournal, and rundll32 .dat/.zip.dll execution
Flags Windows process execution indicative of NotPetya: clearing event logs with wevtutil and deleting C drive USN journal with fsutil.
Florian Roth (Nextron Systems), Tom Ueltschi, Huntrule TeamWindowsprocess_creationCritical123Free2019-01-16Windows PowerShell Remote Thread Creation Into Uncommon Target Processes
Alerts on PowerShell creating remote threads in rundll32.exe or regsvr32.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_remote_threadMedium175Free2018-06-25Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Alerts when mshta/PowerShell and similar script hosts spawn tasks, download/transfer, or utility tools on Windows.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh218Free2018-04-06Windows rundll32 Trojan Loader Execution via Local AppData and .dat Parameters
Flags rundll32.exe launched with AppData/local .dat and .dll patterns consistent with Trojan loader behavior.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh112Free2018-03-01Windows rundll32 execution matching ZxShell function and remote disk strings
Alerts on rundll32.exe command lines containing zxFunction and RemoteDiskXXXXX indicative of ZxShell execution.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationCritical52Free2017-07-20Windows Process Creation: Fireball Archer installs via rundll32.exe and InstallArcherSvc
Flags rundll32.exe executions referencing InstallArcherSvc in the process command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2017-06-03Windows Rundll32 DLL Load via control.exe spawning
Alerts on control.exe spawning rundll32.exe to load Shell32.dll via DLL invocation patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-04-15