Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
89 rules
PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
sigmaWindowshigh2019-10-08Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
sigmaWindowsmedium2019-01-16Windows: NotPetya indicators via wevtutil log clearing, fsutil deletejournal, and rundll32 .dat/.zip.dll execution
Flags Windows process execution indicative of NotPetya: clearing event logs with wevtutil and deleting C drive USN journal with fsutil.
sigmacritical2019-01-16Windows PowerShell Remote Thread Creation Into Uncommon Target Processes
Alerts on PowerShell creating remote threads in rundll32.exe or regsvr32.exe on Windows.
sigmaWindowsmedium2018-06-25Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Alerts when mshta/PowerShell and similar script hosts spawn tasks, download/transfer, or utility tools on Windows.
sigmaWindowshigh2018-04-06Windows rundll32 Trojan Loader Execution via Local AppData and .dat Parameters
Flags rundll32.exe launched with AppData/local .dat and .dll patterns consistent with Trojan loader behavior.
sigmahigh2018-03-01Windows rundll32 execution matching ZxShell function and remote disk strings
Alerts on rundll32.exe command lines containing zxFunction and RemoteDiskXXXXX indicative of ZxShell execution.
sigmacritical2017-07-20Windows Process Creation: Fireball Archer installs via rundll32.exe and InstallArcherSvc
Flags rundll32.exe executions referencing InstallArcherSvc in the process command line on Windows.
sigmahigh2017-06-03Windows Rundll32 DLL Load via control.exe spawning
Alerts on control.exe spawning rundll32.exe to load Shell32.dll via DLL invocation patterns.
sigmaWindowshigh2017-04-15