Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
144 rules
PowerShell ScriptBlock Logging: Obfuscated RUNDLL Launcher using rundll32.exe and shell32.dll
Identifies PowerShell script content invoking rundll32.exe/shell32.dll via shellexec_rundll and referencing PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium152Free2020-10-18PowerShell module activity launching rundll32 via shell32.dll obfuscation content
Alerts when PowerShell module payloads reference a shell32/rundll32 launcher pattern that includes PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleMedium173Free2020-10-18Windows System: Detect rundll32 Service Control Manager launches PowerShell via obfuscated parameters
Flags service creation where ImagePath uses rundll32/shell32 (shellexec_rundll) to invoke PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemMedium80Free2020-10-18Windows Security 4697: Obfuscated PowerShell via rundll32 shell32 shellexec_rundll
Alert on Security EID 4697 where service installation references rundll32/shell32.dll to launch PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityMedium80Free2020-10-18Windows Service Control Manager Rundll32 Obfuscation via Command-Line Encoded PowerShell
Detects service creation where ImagePath invokes rundll32 (shell32) with command-chain tokens indicative of obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh100Free2020-10-09Windows Security 4697: Obfuscated command uses rundll32 with shell32.dll
Alerts on EventID 4697 service command lines containing rundll32 with shell32.dll/shellexec_rundll and obfuscation-like script fragments.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh112Free2020-10-09Rundll32 Executes Setupapi.dll InstallHinfSection via Runonce.exe
Alerts when rundll32 passes setupapi.dll::InstallHinfSection arguments that result in launching runonce.exe.
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium335Free2020-10-07Windows: Rundll32 LaunchApplication via pcwutl.dll
Flags rundll32.exe using pcwutl.dll to invoke LaunchApplication.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium163Free2020-10-05Windows TAIDOOR RAT DLL Load via rundll32 Command Line
Detects Windows process creation command lines consistent with TAIDOOR RAT DLL loading through rundll32.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh183Free2020-07-30Windows process execution matching Winnti RedMimicry playbook (rundll32/cmd with temp batch and gthread/sigcmm DLLs)
Flags rundll32.exe/cmd.exe launches with Winnti-specific DLL and temp batch indicators.
Alexander Rausch, Huntrule TeamWindowsprocess_creationHigh40Free2020-06-24Windows rundll32 WebDAV Client Execution (davclnt.dll DavSetCookie)
Flags svchost.exe spawning rundll32.exe to run davclnt.dll,DavSetCookie, consistent with WebDAV client execution.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium60Free2020-05-02Windows Process Memory Dump via comsvcs.dll using rundll32
Alert on rundll32 loading comsvcs.dll with arguments consistent with a full process memory dump.
Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2020-02-18Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Alert on Windows executions where a SYSTEM-integrity child is spawned by a LOCAL SERVICE or NETWORK SERVICE parent, excluding a specific rundll32 pattern.
Teymur Kheirkhabarov, Roberto Rodriguez (@Cyb3rWard0g), Open Threat Research (OTR), Huntrule TeamWindowsprocess_creationHigh219Free2019-10-26Rundll32.exe DLL Export Calls by Ordinal (Windows Process Creation)
Detects rundll32.exe commands that specify DLL exports by ordinal using “.dll #” syntax.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium100Free2019-10-22PowerShell ScriptBlock uses rundll32 with shell32.dll and obfuscated invoke/comspec/iex
Flags PowerShell script blocks containing rundll32/shell32.dll execution strings alongside invoke/iex/comspec patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh60Free2019-10-08