MITRE ATT&CK technique
User Execution detection rulesT1204
User Execution (T1204) is a MITRE ATT&CK technique in the Execution tactic. This page lists the 57 community-maintained Sigma detection rules in the library mapped to T1204 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, macos, linux.
DarkSide Ransomware Pattern
criticalDetects DarkSide Ransomware and helpers
windows · process_creation
Droppers Exploiting CVE-2017-11882
criticalDetects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
windows · process_creation
Exploit for CVE-2017-8759
criticalDetects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759
windows · process_creation
Potential Maze Ransomware Activity
criticalDetects specific process characteristics of Maze ransomware word document droppers
windows · process_creation
PrinterNightmare Mimikatz Driver Name
criticalDetects static QMS 810 and mimikatz driver name used by Mimikatz as exploited in CVE-2021-1675 and CVE-2021-34527
windows · registry_event
Ursnif Malware C2 URL Pattern
criticalDetects Ursnif C2 traffic.
proxy
Antivirus - Hacktool Signature
highDetects a highly relevant Antivirus alert that reports a hack tool or other attack tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
File With Uncommon Extension Created By An Office Application
highDetects the creation of files with an executable or script extension by an Office application.
windows · file_event
FileFix - Command Evidence in TypedPaths
highDetects commonly-used chained commands and strings in the most recent 'url' value of the 'TypedPaths' key, which could be indicative of a user being targeted by the FileFix technique.
windows · registry_set
Flash Player Update from Suspicious Location
highDetects a flashplayer update from an unofficial location
proxy
GAC DLL Loaded Via Office Applications
highDetects any GAC DLL being loaded by an Office Product
windows · image_load
HackTool - LittleCorporal Generated Maldoc Injection
highDetects the process injection of a LittleCorporal generated Maldoc.
windows · process_access
Kapeka Backdoor Loaded Via Rundll32.EXE
highDetects the Kapeka Backdoor binary being loaded by rundll32.exe. The Kapeka loader drops a backdoor, which is a DLL with the '.wll' extension masquerading as a Microsoft Word Add-In.
windows · image_load
MMC Executing Files with Reversed Extensions Using RTLO Abuse
highDetects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.
windows · process_creation
Potential ClickFix Execution Pattern - Registry
highDetects potential ClickFix malware execution patterns by monitoring registry modifications in RunMRU keys containing HTTP/HTTPS links. ClickFix is known to be distributed through phishing campaigns and uses techniques like clipboard hijacking and fake CAPTCHA pages. Through the fakecaptcha pages, the adversary tricks users into opening the Run dialog box and pasting clipboard-hijacked content, such as one-liners that execute remotely hosted malicious files or scripts.
windows · registry_set
Potential Snatch Ransomware Activity
highDetects specific process characteristics of Snatch ransomware word document droppers
windows · process_creation
Suspicious Binaries and Scripts in Public Folder
highDetects the creation of a file with a suspicious extension in the public folder, which could indicate potential malicious activity.
windows · file_event
Suspicious Binary In User Directory Spawned From Office Application
highDetects an executable in the users directory started from one of the Microsoft Office suite applications (Word, Excel, PowerPoint, Publisher, Visio)
windows · process_creation
Suspicious ClickFix/FileFix Execution Pattern
highDetects suspicious execution patterns where users are tricked into running malicious commands via clipboard manipulation, either through the Windows Run dialog (ClickFix) or File Explorer address bar (FileFix). Attackers leverage social engineering campaigns—such as fake CAPTCHA challenges or urgent alerts—encouraging victims to paste clipboard contents, often executing mshta.exe, powershell.exe, or similar commands to infect systems.
windows · process_creation
Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
highDetects process creation with suspicious whitespace padding followed by a '#' character, which may indicate ClickFix or FileFix techniques used to conceal malicious commands from visual inspection. ClickFix and FileFix are social engineering attack techniques where adversaries distribute phishing documents or malicious links that deceive users into opening the Windows Run dialog box or File Explorer search bar. The victims are then instructed to paste commands from their clipboard, which contain extensive whitespace padding using various Unicode space characters to push the actual malicious command far to the right, effectively hiding it from immediate view.
windows · process_creation
Suspicious FileFix Execution Pattern
highDetects suspicious FileFix execution patterns where users are tricked into running malicious commands through browser file upload dialog manipulation. This attack typically begins when users visit malicious websites impersonating legitimate services or news platforms, which may display fake CAPTCHA challenges or direct instructions to open file explorer and paste clipboard content. The clipboard content usually contains commands that download and execute malware, such as information stealing tools.
windows · process_creation
Suspicious LNK Command-Line Padding with Whitespace Characters
highDetects exploitation of LNK file command-line length discrepancy, where attackers hide malicious commands beyond the 260-character UI limit while the actual command-line argument field supports 4096 characters using whitespace padding (e.g., 0x20, 0x09-0x0D). Adversaries insert non-printable whitespace characters (e.g., Line Feed \x0A, Carriage Return \x0D) to pad the visible section of the LNK file, pushing malicious commands past the UI-visible boundary. The hidden payload, executed at runtime but invisible in Windows Explorer properties, enables stealthy execution and evasion—commonly used for social engineering attacks. This rule flags suspicious use of such padding observed in real-world attacks.
windows · process_creation
Suspicious Microsoft Office Child Process
highDetects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)
windows · process_creation
Suspicious Microsoft Office Child Process - MacOS
highDetects suspicious child processes spawning from microsoft office suite applications such as word or excel. This could indicates malicious macro execution
macos · process_creation
Suspicious Outlook Child Process
highDetects a suspicious process spawning from an Outlook process.
windows · process_creation
Suspicious Space Characters in RunMRU Registry Path - ClickFix
highDetects the occurrence of numerous space characters in RunMRU registry paths, which may indicate execution via phishing lures using clickfix techniques to hide malicious commands in the Windows Run dialog box from naked eyes.
windows · registry_set
Suspicious Space Characters in TypedPaths Registry Path - FileFix
highDetects the occurrence of numerous space characters in TypedPaths registry paths, which may indicate execution via phishing lures using file-fix techniques to hide malicious commands.
windows · registry_set
Suspicious Startup Folder Persistence
highDetects the creation of potentially malicious script and executable files in Windows startup folders, which is a common persistence technique used by threat actors. These files (.ps1, .vbs, .js, .bat, etc.) are automatically executed when a user logs in, making the Startup folder an attractive target for attackers. This technique is frequently observed in malvertising campaigns and malware distribution where attackers attempt to maintain long-term access to compromised systems.
windows · file_event
Suspicious WMIC Execution Via Office Process
highOffice application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).
windows · process_creation
Suspicious WmiPrvSE Child Process
highDetects suspicious and uncommon child processes of WmiPrvSE
windows · process_creation
Symlink Etc Passwd
highDetects suspicious command lines that look as if they would create symbolic links to /etc/passwd
linux
TanStack Supply-Chain Attack Execution Indicators - Linux
highDetects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026. The preinstall hook runs setup.mjs, which downloads a platform-specific Bun runtime.
linux · process_creation
TanStack Supply-Chain Attack Execution Indicators - Windows
highDetects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath reported on early May 2026.
windows · process_creation
VBA DLL Loaded Via Office Application
highDetects VB DLL's loaded by an office application. Which could indicate the presence of VBA Macros.
windows · image_load
AppLocker Application Would Have Been Blocked
mediumDetects when AppLocker "Audit only" enforcement mode reports that an Application, DLL, Script, MSI, or Packaged-App would have been blocked if AppLocker "Enforce rules" enforcement mode was enabled.
windows
AppLocker Prevented Application or Script from Running
mediumDetects when AppLocker prevents the execution of an Application, DLL, Script, MSI, or Packaged-App from running.
windows
Arbitrary Shell Command Execution Via Settingcontent-Ms
mediumThe .SettingContent-ms file type was introduced in Windows 10 and allows a user to create "shortcuts" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.
windows · process_creation
CLR DLL Loaded Via Office Applications
mediumDetects CLR DLL being loaded by an Office Product
windows · image_load
DotNET Assembly DLL Loaded Via Office Application
mediumDetects any assembly DLL being loaded by an Office Product
windows · image_load
Exploit for CVE-2017-0261
mediumDetects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
windows · process_creation
Microsoft Excel Add-In Loaded From Uncommon Location
mediumDetects Microsoft Excel loading an Add-In (.xll) file from an uncommon location
windows · image_load
Microsoft VBA For Outlook Addin Loaded Via Outlook
mediumDetects outlvba (Microsoft VBA for Outlook Addin) DLL being loaded by the outlook process
windows · image_load
Payload Decoded and Decrypted via Built-in Utilities
mediumDetects when a built-in utility is used to decode and decrypt a payload after a macOS disk image (DMG) is executed. Malware authors may attempt to evade detection and trick users into executing malicious code by encoding and encrypting their payload and placing it in a disk image file. This behavior is consistent with adware or malware families such as Bundlore and Shlayer.
macos · process_creation
Potential Suspicious Browser Launch From Document Reader Process
mediumDetects when a browser process or browser tab is launched from an application that handles document files such as Adobe, Microsoft Office, etc. And connects to a web application over http(s), this could indicate a possible phishing attempt.
windows · process_creation
Potentially Suspicious WebDAV LNK Execution
mediumDetects possible execution via LNK file accessed on a WebDAV server.
windows · process_creation
Remote DLL Load Via Rundll32.EXE
mediumDetects a remote DLL load event via "rundll32.exe".
windows · image_load
Suspicious Execution via macOS Script Editor
mediumDetects when the macOS Script Editor utility spawns an unusual child process.
macos · process_creation
Windows AppX Deployment Full Trust Package Installation
mediumDetects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
windows
Windows AppX Deployment Unsigned Package Installation
mediumDetects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events
windows
Download From Suspicious TLD - Blacklist
lowDetects download of certain file types from hosts in suspicious TLDs
proxy
Download From Suspicious TLD - Whitelist
lowDetects executable downloads from suspicious remote systems
proxy
Microsoft Excel Add-In Loaded
lowDetects Microsoft Excel loading an Add-In (.xll) file
windows · image_load
Microsoft Word Add-In Loaded
lowDetects Microsoft Word loading an Add-In (.wll) file which can be used by threat actors for initial access or persistence.
windows · image_load
Successful MSIX/AppX Package Installation
lowDetects successful MSIX/AppX package installations on Windows systems by monitoring EventID 854 in the Microsoft-Windows-AppXDeployment-Server/Operational log. While most installations are legitimate, this can help identify unauthorized or suspicious package installations. It is crucial to monitor such events as threat actors may exploit MSIX/AppX packages to deliver and execute malicious payloads.
windows
Suspicious Deno File Written from Remote Source
lowDetects Deno writing a file from a direct HTTP(s) call and writing to the appdata folder or bringing it's own malicious DLL. This behavior may indicate an attempt to execute remotely hosted, potentially malicious files through deno.
windows · file_event
Windows MSIX Package Support Framework AI_STUBS Execution
lowDetects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.
windows · process_creation
New Application in AppCompat
informationalA General detection for a new application in AppCompat. This indicates an application executing for the first time on an endpoint.
windows · registry_set