Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
49 rules
Suspicious LucidRook DLL Side-Loading via Renamed msedge.exe
This rule detects msedge.exe executing from a WindowsApps directory under the user profile, matching the LucidRook loader that renames the DISM index.exe binary to msedge.exe to side-load a malicious DismCore.dll. Legitimate Microsoft Edge runs from Program Files, so an msedge.exe launched from AppData WindowsApps is an impostor used for search-order hijacking. This behavior indicates initial execution of the Lua-based LucidRook malware.
HuntRule TeamWindowsprocess_creationHigh122Premium2026-05-17Malicious DLL Side-Loading of vcl120.bpl From AppData via HijackLoader (via image_load)
This rule detects a vcl120.bpl Delphi runtime package being loaded from a user AppData Roaming directory, the side-loading step used by the IObit-abusing HijackLoader to stage AsyncRAT. The legitimate vcl120.bpl resides with its application, not under AppData.
HuntRule TeamWindowsimage_loadHigh131Premium2026-05-17DLL Side-Loading of WebUI.dll via Iscrpaint Host Binary
This rule detects the iscrpaint.exe binary loading WebUI.dll, the DLL side-loading pair used to run LummaStealer under a signed host process. Loading this companion DLL from the malware staging directory indicates search-order hijacking rather than legitimate application behavior.
HuntRule TeamWindowsimage_loadHigh182Premium2026-05-14Suspicious ADNotificationManager Execution for netutils.dll Side-Loading (via process_creation)
This rule detects the Adobe ADNotificationManager.exe binary running from a user writable directory rather than its installed Adobe program path, where the RedCurl EarthKapre APT side-loads a malicious netutils.dll. Relocating the signed executable lets the attacker force loading of an attacker controlled library beside it. Execution of this Adobe component from a temporary or profile path is a strong side-loading indicator.
HuntRule TeamWindowsprocess_creationHigh162Premium2026-05-08Malicious JanelaRAT DLL Side-Loading via nevasca.exe (via image_load)
This rule detects the host binary nevasca.exe loading the malicious PixelPaint.dll used by JanelaRAT to hijack execution flow through DLL side-loading. JanelaRAT is a financial remote access trojan targeting users in Latin America. Detecting this loader pair exposes the in-memory execution of the RAT before command-and-control is established.
HuntRule TeamWindowsimage_loadHigh71Premium2026-05-07Malicious CRYPTBASE.dll Side-Loading Outside System32
This rule detects CRYPTBASE.dll being loaded from a directory outside the Windows System32 folder. The CPU-Z and HWMonitor watering-hole campaign side-loaded a malicious CRYPTBASE.dll next to a trusted binary to hijack execution as reported by Kaspersky. Because the genuine CRYPTBASE.dll ships only in System32, loading it from any other path is a reliable DLL search-order hijack indicator.
HuntRule TeamWindowsimage_loadHigh113Premium2026-05-01Windows DLL Side-Loading: OleView loading aclui.dll
Alerts on OleView.exe loading aclui.dll on Windows, excluding common benign paths to highlight potential DLL side-loading.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh232Free2024-07-31Windows DLL side-loading: KeyScramblerIE.DLL loaded by KeyScrambler.exe
Alerts on KeyScrambler.exe loading KeyScramblerIE.dll, a common DLL side-loading pattern that may indicate malicious library execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh489Free2024-04-15Windows DLL Side-Loading via ProgramData Image Load Indicators (clip.exe and wsmprovhost.exe)
Flags ProgramData clip.exe or wsmprovhost.exe launching with suspicious DLL loads from ProgramData.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh93Free2023-10-24Windows DLL side-loading via appverifUI.dll image loads
Alerts when appverifUI.dll is loaded on Windows from unexpected paths, a common DLL sideloading technique.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh214Free2023-06-20Windows DLL Sideloading Suspicion via edputil.dll Image Load
Alerts on edputil.dll image loads occurring outside standard Windows system directories, suggesting possible DLL side-loading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh112Free2023-06-09Windows Wazuh Platform DLL Side-Loading via ImageLoad of libwazuhshared.dll
Alerts on suspicious loading of Wazuh platform DLLs in Windows image load telemetry, excluding common Program Files and Mingw64 patterns.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium151Free2023-03-13Windows vmnat.exe Renamed Execution for Possible DLL Side-Loading
Alerts on Windows processes where vmnat.exe appears renamed, which may support stealthy execution and DLL side-loading behavior.
elhoim, Huntrule TeamWindowsprocess_creationHigh103Free2022-09-09Windows Defender mpclient.dll Side-loading: MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when MpCmdRun.exe or NisSrv.exe runs from non-default directories, a common indicator of possible mpclient.dll sideloading.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh394Free2022-08-01Windows: msdt.exe Loads sdiageng.dll via Image Load Events
Flags msdt.exe image-load events that load sdiageng.dll, a behavior commonly associated with DLL side-loading abuse.
Greg (rule), Huntrule TeamWindowsimage_loadHigh169Free2022-06-17