Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
144 rules
Windows Qakbot-associated Rundll32 execution via suspicious parent process and export strings
Flags rundll32.exe executions tied to Qakbot-style export strings when launched by script/cmd utilities.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical81Free2023-05-24Windows rundll32.exe Execution via cmd/cscript/powershell with .dll and Suspicious Directories
Alerts on rundll32.exe execution with DLL arguments from common Windows script/LOLBins and suspicious staging paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-05-24Windows: Rundll32 Executions Using Obfuscated Ordinal Call Arguments
Flags rundll32.exe launches with command-line ordinal obfuscation patterns.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2023-05-17Windows: Suspicious rundll32 Execution of advpack.dll with Ordinal RegisterOCX Calls
Identifies rundll32.exe launching advpack.dll with ordinal-style calls consistent with stealthy OCX registration behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2023-05-17Suspicious rundll32/regsvr32/msiexec Child Process from Windows Script Hosts (cscript/wscript)
Alerts on wscript/cscript spawning suspicious child processes or scripts that invoke rundll32/regsvr32/msiexec.
Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'), Huntrule TeamWindowsprocess_creationMedium124Free2023-05-15Windows Service Creation for Backdoor Persistence via GoogleUpdate (Event ID 7045)
Flags creation of a "GoogleUpdate" Windows service with rundll32/FileProtocolHandler image path pointing to ProgramData persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemCritical504Free2023-05-15Windows rundll32 Cleanup Export Execution via msupdate Service Host (ColdSteel)
Flags svchost.exe msupdate-style services spawning rundll32.exe to run cleanup-related exports.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical151Free2023-04-30Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
Alerts on svchost.exe launching rundll32.exe to run davclnt.dll DavSetCookie for WebDav over a non-local IP.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2023-03-16Windows Rundll32 Execution Masquerading as Image Files via Image Extensions
Flags rundll32.exe executions whose command line references image file extensions used for DLL masquerading.
Hieu Tran, Huntrule TeamWindowsprocess_creationHigh91Free2023-03-13Windows: Rundll32 Launching NSIS Module for Stealer Capability
Alerts on rundll32.exe execution tied to NSIS module loading indicators (nsis_uns and PrintUIEntry) in the command line.
TropChaud, Huntrule TeamWindowsprocess_creationMedium113Free2023-01-26Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
Detects rundll32 executions that reference DLLs stored in Alternate Data Streams via ADS-style paths.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamWindowsprocess_creationHigh103Free2023-01-21Windows process creation: Suspicious child processes from WindowsApps directory
Alerts on suspicious cmd/PowerShell/mshta/rundll32-style child processes launched from Program Files\WindowsApps.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2023-01-12Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE
Alerts on suspicious children spawned by wermgr.exe using common execution utilities, with a rundll32 WerConCpl exclusion.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2022-10-14Windows Remote Thread Creation via rundll32 Triggered by wab*, wabmig, or ImagingDevices
Alerts on remote thread creation targeting rundll32.exe from wab* or ImagingDevices.exe process images on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_remote_threadHigh236Free2022-09-27Windows Rundll32 Masquerading: DllRegisterServer CommandLine Not Using rundll32.exe
Alerts when 'DllRegisterServer' appears in the command line while the executing image is not rundll32.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh441Free2022-08-22