Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
144 rules
Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
bohops, Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh153Free2021-10-08Windows spoolsv.exe Child Process Execution Indicators
Flags suspicious process executions where spoolsv.exe (print spooler) spawns utility, scripting, or rundll32 children with high integrity.
Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule), Huntrule TeamWindowsprocess_creationHigh191Free2021-07-11Windows Rundll32 Loads DLL Export StartNodeRelay (F-Secure C3)
Flags rundll32.exe launching a DLL that references the StartNodeRelay export in its command line.
Alfie Champion (ajpc500), Huntrule TeamWindowsprocess_creationCritical435Free2021-06-02Windows Rundll32 Used to Start Cobalt Strike DLL Load via StartW
Alerts on rundll32.exe command lines that include a .dll and StartW function, consistent with Cobalt Strike DLL loading.
Wojciech Lesicki, Huntrule TeamWindowsprocess_creationHigh163Free2021-06-01Windows rundll32.exe Started Without Command-Line Parameters
Alerts on Windows process launches of rundll32.exe with no parameters, excluding likely benign parent paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2021-05-27Windows Process Creation: rundll32.exe Command Line Invoking .sys Files
Flags Windows rundll32.exe executions whose command line references .sys file patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2021-03-05Windows rundll32 Executing Inline VBScript via RegRead
Detects rundll32.exe command lines containing inline VBScript execution with RegRead and window.close.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh398Free2021-03-05Windows Process Creation: Detect ShimCache Flush via rundll32 apphelp.dll/kernel32.dll
Flags rundll32 command-line activity that flushes ShimCache via apphelp.dll or kernel32.dll entry points.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2021-02-01Windows rundll32.exe execution with no parameters or arguments
Alerts on Windows rundll32.exe being started with an empty/no-parameter command line.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowsprocess_creationHigh131Free2021-01-31Windows Process Creation: 7z Archive Creation with Script/Command Launch Chaining
Flags Windows process creation chaining 7z archive commands with .zip plus .txt/.log extensions and wscript+rundll32 context.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2021-01-22Windows PowerShell Command Lines with WMI Process Creation and rundll32 Invocation
Flags Windows command lines where PowerShell/WMI is used to spawn rundll32 from c:\windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical173Free2021-01-20Windows rundll32.exe Command-Line RunDLL or Control_RunDLL Execution
Alerts on rundll32.exe process launches whose command lines end with RunDLL/Control_RunDLL, indicative of DLL function loading.
FPT.EagleEye, Huntrule TeamWindowsprocess_creationCritical201Free2020-12-25Windows Process Tree: rundll32.exe launching wermgr.exe via DllRegisterServer
Flags rundll32.exe spawning wermgr.exe where rundll32 command line includes DllRegisterServer.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2020-11-26Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32
Alerts on suspicious Windows process launches of key binaries with missing/empty arguments, excluding common Edge/Chromium installer use.
Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh272Free2020-10-23Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_accessHigh171Free2020-10-20