Malicious HackTool - Impersonate Execution (via process_creation)
This rule detects execution of the Impersonate tool. That can be leveraged to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
SigmamediumWindowsv1
sigma
malicious-hacktool-impersonate-execution-via-process-creation
title: Malicious HackTool - Impersonate Execution (via process_creation)
id: 61812769-698b-50ac-908b-b825692ec600
status: stable
description: This rule detects execution of the Impersonate tool. That can be leveraged to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
references:
- https://attack.mitre.org/techniques/T1134/003/
- https://attack.mitre.org/techniques/T1134/001/
- https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/
- https://github.com/sensepost/impersonate
author: Huntrule Team
date: 2026-06-28
tags:
- attack.privilege-escalation
- attack.stealth
- attack.t1134.001
- attack.t1134.003
logsource:
product: windows
category: process_creation
detection:
selection_commandline_exe:
CommandLine|contains: 'impersonate.exe'
selection_commandline_opt:
CommandLine|contains:
- ' list '
- ' exec '
- ' adduser '
selection_hash:
Hashes|contains:
- 'MD5=9520714AB576B0ED01D1513691377D01'
- 'SHA256=E81CC96E2118DC4FBFE5BAD1604E0AC7681960143E2101E1A024D52264BB0A8A'
- 'IMPHASH=0A358FFC1697B7A07D0E817AC740DF62'
condition: all of selection_commandline_* or selection_hash
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.