Skip to content

new: renamed system binaries execution for dll hijacking attack#5891

Open
swachchhanda000 wants to merge 5 commits intoSigmaHQ:masterfrom
swachchhanda000:phoneactivate_sppc
Open

new: renamed system binaries execution for dll hijacking attack#5891
swachchhanda000 wants to merge 5 commits intoSigmaHQ:masterfrom
swachchhanda000:phoneactivate_sppc

Conversation

@swachchhanda000
Copy link
Collaborator

Summary of the Pull Request

Changelog

update: Files With System Process Name In Unsuspected Locations - add new entries
new: Potential DLL Sideloading of SPPC.dll
new: Suspicious Renamed System Binaries Execution
update: System File Execution Location Anomaly - add OriginalFilename

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions bot added Rules Review Needed The PR requires review Windows Pull request add/update windows related rules labels Mar 3, 2026
@@ -0,0 +1,38 @@
title: Suspicious Renamed System Binaries Execution
Copy link
Collaborator

@phantinuss phantinuss Mar 3, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'd prefer either single rules per tool or we group them for the threat report in a emerging thread rule. As I prefer them as general rules, better split them. It's not like we find a nicer umbrella term like "sysinternal tools"/"network utulities"/...
The other solution would be to merge all existing rules for renamed system binaries into this rule but I prefer single rules for the "Renamed" stanza.

I know it's tedious but imo it's better in the long run. (better meta data and maintainability)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants