Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
26 rules
Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.
sigmaWindowshigh2021-08-23Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Alerts on Office spawning WMIC.exe with process/create/call arguments and LOLBIN-like tool references.
sigmaWindowshigh2021-08-23Windows Script and LOLBins Loading .NET CLR DLLs via clr.dll, mscoree.dll, mscorlib.dll
Alerts when common scripting/execution binaries load .NET CLR DLLs like clr.dll and mscoree.dll on Windows.
sigmaWindowshigh2020-10-14Windows manage-bde.wsf via wscript/cscript Proxy Execution
Flags Windows process executions where wscript/cscript runs manage-bde.wsf, indicating potential proxy execution via LOLBIN.
sigmaWindowshigh2020-10-13Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName
Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.
sigmaWindowshigh2019-06-15Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
sigmaWindowsmedium2019-01-16