Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
49 rules
Malicious Unsigned libConfigurer64 Dylib Side-Loading via Image Load
This rule detects loading of the libConfigurer64 dylib which pirated macOS applications side-load to execute the bundled Khepri implant. This uniquely named unsigned library is the loading mechanism of the campaign so its appearance indicates a trojanized pirated app running malicious code.
HuntRule TeamMacosimage_loadHigh121Premium2026-07-13Malicious GHOSTPULSE DLL Side-Loading of libcurl via VBoxSVC
This rule detects the VirtualBox VBoxSVC executable loading a libcurl DLL from outside its normal installation directory which is the side-loading path GHOSTPULSE abuses to execute its stager. The rule excludes loads from genuine VirtualBox directories to focus on the malicious wrong context placement.
HuntRule TeamWindowsimage_loadHigh258Premium2026-07-09Malicious PlugX DLL Side-Loading via iviewers OLE Object Viewer (via image_load)
This rule detects the legitimate iviewers.exe OLE COM Object Viewer loading a co-located iviewers.dll from a non standard directory such as ProgramData. Velvet Ant abused DLL search order hijacking against this signed Windows SDK utility to load a PlugX loader and payload. Legitimate use of this tool loads its DLL from the SDK installation directory only.
HuntRule TeamWindowsimage_loadHigh82Premium2026-07-06Possible DLL Side-Loading via DicomPortable Spawned by ITarian RmmService
This rule detects DicomPortable launched by the ITarian RmmService process which the phishing RMM campaigns abuse to side-load HijackLoader and DeerStealer through a trojanized DLL. Chaining a legitimate RMM service into a vulnerable portable binary lets adversaries execute malware under a trusted parent. Detecting this parent-child pair surfaces DLL search order hijacking used for stealer delivery.
HuntRule TeamWindowsprocess_creationHigh93Premium2026-07-02Malicious DLL Side-Loading of SBAMBRES.DLL by VIPRE Binary via DeedRAT (via image_load)
This rule detects the legitimate VIPRE MambaSafeModeUI.exe binary loading SBAMBRES.DLL from the ProgramData Micro directory, the side-loading step that launches the DeedRAT backdoor. Genuine VIPRE components load this DLL from their install directory, not ProgramData.
HuntRule TeamWindowsimage_loadHigh163Premium2026-07-01Malicious APT29 DLL Side-Loading via msoev.exe from Windows Tasks Directory (via process_creation)
This rule detects the signed msoev binary executing from the Windows Tasks directory, the side-loading launcher APT29 used to load the Duke malware in the German Embassy lure campaign. Running this legitimate binary from C:\Windows\Tasks side-loads a malicious Mso DLL from the same folder. Execution of msoev from this path is highly anomalous.
HuntRule TeamWindowsprocess_creationHigh161Premium2026-06-25Malicious Lazarus DLL Side-Loading of ualapi.dll via spoolsv.exe (via image_load)
This rule detects the Windows Print Spooler process spoolsv.exe loading a ualapi.dll from a directory other than System32. In the Lazarus SIGNBT campaign the actor plants a rogue ualapi.dll that is side-loaded by spoolsv.exe to gain execution and persistence, so a ualapi.dll load from an unusual path indicates print-processor abuse and hijacked system code.
HuntRule TeamWindowsimage_loadHigh73Premium2026-06-22Suspicious Imjp14k DLL Side-Loading From Non-System Path
This rule detects a process loading imjp14k.dll from a path outside the standard Windows System32 directory. APT41 abused DLL side-loading of imjp14k.dll to launch ShadowPad on a compromised Taiwanese network. Side-loading a system-named DLL from a writable non-system directory is a hallmark of hijack execution used to run malicious code under a trusted host process.
HuntRule TeamWindowsimage_loadHigh243Premium2026-06-22Suspicious Renamed MonitoringHost Binary Indicating DLL Side-Loading
This rule detects execution of the signed Microsoft MonitoringHost binary under a renamed file name, a technique used by the SADBRIDGE loader to deploy the GOSAR (Golang QUASAR) backdoor. SADBRIDGE renames MonitoringHost.exe to DevQueryBroker.exe and abuses DLL search order hijacking to side-load a malicious HealthServiceRuntime.dll. Detecting a mismatch between the original file name and the on-disk image name surfaces this masquerading and side-loading activity for triage.
HuntRule TeamWindowsprocess_creationHigh121Premium2026-06-22Malicious DLL Side-Loading of msimg32 via Silverlight.Configuration.exe
This rule detects Silverlight.Configuration.exe loading msimg32.dll from outside the Windows system directories. The Horns and Hooves campaign abused this signed binary to side-load a planted msimg32.dll and execute the NetSupport loader under a trusted process.
HuntRule TeamWindowsimage_loadHigh133Premium2026-06-20Malicious DtlCrashCatch DLL Side-Loading via OneDrive Sync Service by SPECTRALVIPER
This rule detects the OneDrive.Sync.Service.exe process loading DtlCrashCatch.dll, a side-loaded and injected module used by the SPECTRALVIPER backdoor. This activity is associated with the OceanLotus (APT32) espionage campaign that abuses a trusted signed OneDrive binary for DLL search-order hijacking. Catching this specific side-load is important because it reveals code injection and stealthy execution under a legitimate process context.
HuntRule TeamWindowsimage_loadHigh387Premium2026-06-18Malicious PlugX DLL Side-Loading via LMIGuardianSvc from SamsungDriver Directory (via process_creation)
This rule detects the legitimate LMIGuardianSvc binary executing from a SamsungDriver directory created by Mustang Panda to side-load PlugX. The signed binary search-order loads a malicious LMIGuardianDll from this attacker-controlled path. Running this LogMeIn component from a non-standard user directory is anomalous.
HuntRule TeamWindowsprocess_creationHigh217Premium2026-06-12Malicious DLL Side-Loading via AVGApplicationFrameHost
This rule detects the AVGApplicationFrameHost.exe binary loading a wsc.dll module, a DLL side-loading chain used by TheWizards APT group to execute the WizardNet backdoor alongside an encrypted log.dat shellcode payload. Abusing a signed AV-related host process to load an attacker DLL evades trust controls and blends malicious execution into legitimate software.
HuntRule TeamWindowsimage_loadHigh91Premium2026-06-07Malicious regsvr32.exe Spawned by calc.exe via DLL Side-Loading
This rule detects regsvr32.exe launched with the Windows Calculator calc.exe as its parent process. During Qbot infections the side-loaded calc.exe uses regsvr32 to register and execute the trojan payload DLL. Calculator legitimately never spawns regsvr32, so this parent-child chain is a strong indicator of DLL side-loading and proxied code execution.
HuntRule TeamWindowsprocess_creationHigh232Premium2026-06-05Suspicious DLL Side-Loading via vssvc or WorkFolders
This rule detects the trusted binaries vssvc.exe or WorkFolders.exe loading a DLL from outside the Windows system directories. SideWinder abused DLL side-loading against these signed executables to run malicious code under a legitimate process, and loads from non-system paths indicate a planted DLL.
HuntRule TeamWindowsimage_loadMedium62Premium2026-05-23