Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
26 rules
Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Alerts when baaupdate.exe runs typical script/utility processes, an uncommon parent-child execution pattern on Windows.
sigmaWindowshigh2025-10-18Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.
sigmahigh2025-08-01Windows: AddInUtil.exe LoLBin Executed from Non-Standard Directory
Alerts when AddInUtil.exe (AddInUtil.exe) runs from an uncommon directory path on Windows.
sigmaWindowsmedium2023-09-18Suspicious LOLBIN Copy From Windows System Directories Using Windows Copy Tools
Flags cmd/PowerShell/robocopy/xcopy commands that copy known LOLBINs out of System32/SysWOW64/WinSxS.
sigmaWindowshigh2023-08-29Windows: Detect Loading amsi.dll by LOLBIN Processes
Alert on amsi.dll DLL loads initiated by ExtExport.exe, Odbcconf.exe, or Rundll32.exe on Windows.
sigmaWindowsmedium2023-06-01Windows rundll32.exe Execution via cmd/cscript/powershell with .dll and Suspicious Directories
Alerts on rundll32.exe execution with DLL arguments from common Windows script/LOLBins and suspicious staging paths.
sigmahigh2023-05-24Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
sigmaWindowscritical2023-05-04Windows: Renamed Visual Studio NodejsTools PressAnyKey.exe Execution
Flags Windows executions of renamed Microsoft.NodejsTools.PressAnyKey.exe to help spot LOLBIN-style abuse.
sigmaWindowsmedium2023-04-11Windows Scheduled Task Execution of Uncommon Binaries (LOLBin Suspicion)
Alerts when a Windows Scheduled Task runs a process from a set of uncommon/suspicious binary paths.
sigmaWindowsmedium2022-12-05Windows: Detect sftp.exe used as a LOLBIN via -D option
Alerts on Windows executions of sftp.exe using the -D flag with a path argument.
sigmaWindowsmedium2022-11-10Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
sigmaWindowshigh2022-11-01Windows Script Dropped by Signed Applications and LOLBINs
Detects Windows legitimate/signed executables dropping script files (.ps1, .vbs, .js, etc.) to disk, indicating potential script-based abuse.
sigmaWindowshigh2022-08-21Windows Suspicious App and LOLBIN Dropping Executable Files to Disk
Alerts on Windows processes like Office/LOLBINs writing .exe/.dll and other executable-equivalent files to disk.
sigmaWindowshigh2022-08-21Windows Executable Dropping Archive Files via Common LOLBINs and Office Apps
Alerts when Office or other specified Windows binaries create archive files like .zip/.rar/.7z/.diagcab/.appx on disk.
sigmaWindowshigh2022-08-21Windows: Chromium-Based Browser Launched via Script Host with --load-extension
Flags Windows process creation where Chromium browsers are spawned with --load-extension= from common script/LOLBins parents.
sigmaWindowshigh2022-06-19Windows OpenConsole LOLBIN Execution via Process Creation
Alerts when OpenConsole.exe runs (outside a specific Windows Terminal path), potentially used to bypass application whitelisting.
sigmaWindowsmedium2022-06-16Windows: ie4uinit.exe Used from Non-Standard Current Directory
Flags ie4uinit.exe runs whose CurrentDirectory is outside expected system paths, indicating potential LOLBIN misuse.
sigmaWindowsmedium2022-05-07Windows LOLBIN Execution From Abnormal Drive (calc, certutil, mshta, regsvr32, rundll32)
Flags Windows LOLBIN execution when process CurrentDirectory is not empty/null and contains C:\, indicating unusual launch context.
sigmaWindowsmedium2022-01-25Windows Office Macro File Creation Triggered by Script/LOLBin Parent Process
Alerts when macro-enabled Office files are created by common Windows script execution processes.
sigmaWindowshigh2022-01-23Windows mpiexec.exe LOLBin: Flag combination with -n/n 1 for potential arbitrary execution
Alerts on Windows executions of mpiexec.exe with /n 1 or -n 1, correlated to a specific imphash, indicating LOLBin-style behavior.
sigmaWindowshigh2022-01-11