Malicious HackTool - Impersonate Execution (via process_creation)

This rule detects execution of the Impersonate tool. That can be leveraged to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively

SigmamediumWindowsv1
sigma
title: Malicious HackTool - Impersonate Execution (via process_creation)
id: 61812769-698b-50ac-908b-b825692ec600
status: stable
description: This rule detects execution of the Impersonate tool. That can be leveraged to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
references:
    - https://attack.mitre.org/techniques/T1134/003/
    - https://attack.mitre.org/techniques/T1134/001/
    - https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/
    - https://github.com/sensepost/impersonate
author: Huntrule Team
date: 2026-06-28
tags:
    - attack.privilege-escalation
    - attack.stealth
    - attack.t1134.001
    - attack.t1134.003
logsource:
    product: windows
    category: process_creation
detection:
    selection_commandline_exe:
        CommandLine|contains: 'impersonate.exe'
    selection_commandline_opt:
        CommandLine|contains:
            - ' list '
            - ' exec '
            - ' adduser '
    selection_hash:
        Hashes|contains:
            - 'MD5=9520714AB576B0ED01D1513691377D01'
            - 'SHA256=E81CC96E2118DC4FBFE5BAD1604E0AC7681960143E2101E1A024D52264BB0A8A'
            - 'IMPHASH=0A358FFC1697B7A07D0E817AC740DF62'
    condition: all of selection_commandline_* or selection_hash
falsepositives:
    - Unknown
level: medium

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.