Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
45 rules
Windows Script Dropped by Signed Applications and LOLBINs
Detects Windows legitimate/signed executables dropping script files (.ps1, .vbs, .js, etc.) to disk, indicating potential script-based abuse.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh133Free2022-08-21Windows Suspicious App and LOLBIN Dropping Executable Files to Disk
Alerts on Windows processes like Office/LOLBINs writing .exe/.dll and other executable-equivalent files to disk.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh191Free2022-08-21Windows Executable Dropping Archive Files via Common LOLBINs and Office Apps
Alerts when Office or other specified Windows binaries create archive files like .zip/.rar/.7z/.diagcab/.appx on disk.
frack113, Florian Roth, Huntrule TeamWindowsfile_eventHigh237Free2022-08-21Windows: Chromium-Based Browser Launched via Script Host with --load-extension
Flags Windows process creation where Chromium browsers are spawned with --load-extension= from common script/LOLBins parents.
Aedan Russell, frack113, X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh100Free2022-06-19Windows OpenConsole LOLBIN Execution via Process Creation
Alerts when OpenConsole.exe runs (outside a specific Windows Terminal path), potentially used to bypass application whitelisting.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium319Free2022-06-16Windows: ie4uinit.exe Used from Non-Standard Current Directory
Flags ie4uinit.exe runs whose CurrentDirectory is outside expected system paths, indicating potential LOLBIN misuse.
frack113, Huntrule TeamWindowsprocess_creationMedium415Free2022-05-07Windows LOLBIN Execution From Abnormal Drive (calc, certutil, mshta, regsvr32, rundll32)
Flags Windows LOLBIN execution when process CurrentDirectory is not empty/null and contains C:\, indicating unusual launch context.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Angelo Violetti - SEC Consult '@angelo_violetti', Aaron Herman, Huntrule TeamWindowsprocess_creationMedium92Free2022-01-25Windows Office Macro File Creation Triggered by Script/LOLBin Parent Process
Alerts when macro-enabled Office files are created by common Windows script execution processes.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh143Free2022-01-23Windows mpiexec.exe LOLBin: Flag combination with -n/n 1 for potential arbitrary execution
Alerts on Windows executions of mpiexec.exe with /n 1 or -n 1, correlated to a specific imphash, indicating LOLBin-style behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2022-01-11Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.
Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh396Free2021-08-23Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Alerts on Office spawning WMIC.exe with process/create/call arguments and LOLBIN-like tool references.
Vadim Khrykov, Cyb3rEng, Huntrule TeamWindowsprocess_creationHigh162Free2021-08-23Windows Script and LOLBins Loading .NET CLR DLLs via clr.dll, mscoree.dll, mscorlib.dll
Alerts when common scripting/execution binaries load .NET CLR DLLs like clr.dll and mscoree.dll on Windows.
omkar72, oscd.community, Huntrule TeamWindowsimage_loadHigh4310Free2020-10-14Windows manage-bde.wsf via wscript/cscript Proxy Execution
Flags Windows process executions where wscript/cscript runs manage-bde.wsf, indicating potential proxy execution via LOLBIN.
oscd.community, Natalia Shornikova, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2020-10-13Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName
Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.
Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh286Free2019-06-15Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
juju4, Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium155Free2019-01-16