Browse Rules

Search and filter across all detection sources

399 rules

sigma low sigma

Amsi.DLL Load By Uncommon Process

Detects loading of Amsi.dll by uncommon processes

anvilogic high other

DLL Execution from Uncommon Process [snowflake-crowdstrikefdr_process]

During an attack using Ursnif malware, threat actors were observed executing DLLs with a renamed rundll32 binary. This use case detects execution of the DLL functions DllRegisterServer, DllMain, DllUnregisterServer, DllInstall, or DllCanUnloadNow from processes other than rundll32.exe. Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN)

hayabusa low sigma

Amsi.DLL Load By Uncommon Process

Detects loading of Amsi.dll by uncommon processes

sigma medium sigma

CredUI.DLL Loaded By Uncommon Process

Detects loading of "credui.dll" and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of "CredUIPromptForCredentials" or "CredUnPackAuthenticationBufferW".

hayabusa medium sigma

CredUI.DLL Loaded By Uncommon Process

Detects loading of "credui.dll" and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of "CredUIPromptForCredentials" or "CredUnPackAuthenticationBufferW".

anvilogic high spl

DLL Execution from Uncommon Process [splunk-winevent]

During an attack using Ursnif malware, threat actors were observed executing DLLs with a renamed rundll32 binary. This use case detects execution of the DLL functions DllRegisterServer, DllMain, DllUnregisterServer, DllInstall, or DllCanUnloadNow from processes other than rundll32.exe. Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN)

chronicle high yara-l

Process Memory Dump Via Comsvcs.DLL

Detects a process memory dump via comsvcs.dll using rundll32, covering multiple different techniques

anvilogic high spl

DLL Execution from Uncommon Process [splunk-edr]

During an attack using Ursnif malware, threat actors were observed executing DLLs with a renamed rundll32 binary. This use case detects execution of the DLL functions DllRegisterServer, DllMain, DllUnregisterServer, DllInstall, or DllCanUnloadNow from processes other than rundll32.exe. Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN)

anvilogic high spl

DLL Execution from Uncommon Process [splunk-powershell]

During an attack using Ursnif malware, threat actors were observed executing DLLs with a renamed rundll32 binary. This use case detects execution of the DLL functions DllRegisterServer, DllMain, DllUnregisterServer, DllInstall, or DllCanUnloadNow from processes other than rundll32.exe. Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN)

anvilogic high spl

DLL Execution from Uncommon Process [splunk-sysmon]

During an attack using Ursnif malware, threat actors were observed executing DLLs with a renamed rundll32 binary. This use case detects execution of the DLL functions DllRegisterServer, DllMain, DllUnregisterServer, DllInstall, or DllCanUnloadNow from processes other than rundll32.exe. Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN)

sigma high sigma

Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs

Detects suspicious process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace. These DLLs contain functions like MiniDumpWriteDump that can be abused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll, dbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.

elastic-protections high eql

Potential Protected Process DLL Injection via RPC

Identifies when a process running as protected process loads an unsigned DLL. This may indicate an attempt to bypass Process Protection and inject malicious code.

hayabusa high sigma

Dllhost.EXE Execution Anomaly

Detects a "dllhost" process spawning with no commandline arguments which is very rare to happen and could indicate process injection activity or malware mimicking similar system processes.

sigma high sigma

Dllhost.EXE Execution Anomaly

Detects a "dllhost" process spawning with no commandline arguments which is very rare to happen and could indicate process injection activity or malware mimicking similar system processes.

hayabusa high sigma

Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs

Detects suspicious process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace. These DLLs contain functions like MiniDumpWriteDump that can be abused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll, dbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.

hayabusa high sigma

Dllhost.EXE Execution Anomaly

Detects a "dllhost" process spawning with no commandline arguments which is very rare to happen and could indicate process injection activity or malware mimicking similar system processes.

sigma medium sigma

Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE

Detects potential DLL sideloading of "libcurl.dll" by the "gup.exe" process from an uncommon location

sigma medium sigma

Unsigned Image Loaded Into LSASS Process

Loading unsigned image (DLL, EXE) into LSASS process

splunk unknown spl

Windows NetSupport RMM DLL Loaded By Uncommon Process

The following analytic detects the loading of specific dynamic-link libraries (DLLs) associated with the NetSupport Remote Manager (RMM) tool by any process on a Windows system. Modules such as CryptPak.dll, HTCTL32.DLL, IPCTL32.DLL, keyshowhook.dll, pcicapi.DLL, PCICL32.DLL, and TCCTL32.DLL, are integral to NetSupport's functionality. This detection is particularly valuable when these modules are loaded by processes running from unusual directories (e.g., Downloads, ProgramData, or user-specifi

chronicle unknown yara-l

process_dump_via_comsvcs_dll

Detects process memory dump via comsvcs.dll and rundll32 License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

hayabusa medium sigma

Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE

Detects potential DLL sideloading of "libcurl.dll" by the "gup.exe" process from an uncommon location

hayabusa medium sigma

Unsigned Image Loaded Into LSASS Process

Loading unsigned image (DLL, EXE) into LSASS process

sigma low sigma

BITS Client BitsProxy DLL Loaded By Uncommon Process

Detects an uncommon process loading the "BitsProxy.dll". This DLL is used when the BITS COM instance or API is used. This detection can be used to hunt for uncommon processes loading this DLL in your environment. Which may indicate potential suspicious activity occurring.

hayabusa low sigma

BITS Client BitsProxy DLL Loaded By Uncommon Process

Detects an uncommon process loading the "BitsProxy.dll". This DLL is used when the BITS COM instance or API is used. This detection can be used to hunt for uncommon processes loading this DLL in your environment. Which may indicate potential suspicious activity occurring.

hayabusa high sigma

Process Memory Dump Via Comsvcs.DLL

Detects a process memory dump via "comsvcs.dll" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)