Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
45 rules
Malicious DLL Sideloading via LOLBins from ProgramData by Dohdoor
This rule detects trusted Windows utilities loading propsys or batmeter DLLs from ProgramData or the Public directory. The Dohdoor campaign sideloads its payload through living-off-the-land binaries such as OpenWith and mblctr running from unusual paths. A signed utility loading a system-named DLL from a writable directory is a strong sideloading indicator.
HuntRule TeamWindowsimage_loadHigh464Premium2026-05-10Suspicious MSBuild LOLBin Spawning Script Interpreter (via process_creation)
This rule detects MSBuild.exe spawning PowerShell or cmd child processes which indicates inline task code execution abused as a signed binary proxy. Legitimate build automation rarely has MSBuild directly launching interactive script interpreters.
—Windowsprocess_creationMedium111Premium2026-05-06Malicious LOLBin Download Saved as Windows Utility ping.exe via certutil or curl
This rule detects use of certutil or curl to download a remote file and save it under the name of a legitimate Windows utility such as ping.exe. The Mysterious Elephant APT used this masquerading technique to stage payloads disguised as trusted system binaries. Writing downloaded content to a well-known utility name in a non-System32 location is a strong indicator of ingress tool transfer combined with defense evasion.
HuntRule TeamWindowsprocess_creationHigh294Premium2026-05-01Malicious LOLBin Spawned by Outlook via MonikerLink CVE-2024-21413
This rule detects Microsoft Outlook spawning script interpreters or living off the land binaries such as mshta which is a hallmark of the MonikerLink CVE-2024-21413 exploitation chain. Successful exploitation lets an attacker bypass the Protected View warning and achieve code execution from a crafted email which makes any such child process highly suspicious.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-05-01Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Alerts when baaupdate.exe runs typical script/utility processes, an uncommon parent-child execution pattern on Windows.
andrewdanis, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh130Free2025-10-18Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.
Nisarg Suthar, Huntrule TeamWindowsprocess_creationHigh249Free2025-08-01Windows: AddInUtil.exe LoLBin Executed from Non-Standard Directory
Alerts when AddInUtil.exe (AddInUtil.exe) runs from an uncommon directory path on Windows.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium184Free2023-09-18Suspicious LOLBIN Copy From Windows System Directories Using Windows Copy Tools
Flags cmd/PowerShell/robocopy/xcopy commands that copy known LOLBINs out of System32/SysWOW64/WinSxS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh193Free2023-08-29Windows: Detect Loading amsi.dll by LOLBIN Processes
Alert on amsi.dll DLL loads initiated by ExtExport.exe, Odbcconf.exe, or Rundll32.exe on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium326Free2023-06-01Windows rundll32.exe Execution via cmd/cscript/powershell with .dll and Suspicious Directories
Alerts on rundll32.exe execution with DLL arguments from common Windows script/LOLBins and suspicious staging paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-05-24Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical415Free2023-05-04Windows: Renamed Visual Studio NodejsTools PressAnyKey.exe Execution
Flags Windows executions of renamed Microsoft.NodejsTools.PressAnyKey.exe to help spot LOLBIN-style abuse.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3010Free2023-04-11Windows Scheduled Task Execution of Uncommon Binaries (LOLBin Suspicion)
Alerts when a Windows Scheduled Task runs a process from a set of uncommon/suspicious binary paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowstaskschedulerMedium163Free2022-12-05Windows: Detect sftp.exe used as a LOLBIN via -D option
Alerts on Windows executions of sftp.exe using the -D flag with a path argument.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium163Free2022-11-10Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh337Free2022-11-01