Windows: Detects NetSupport RAT client32.exe execution using Imphash and filename metadata

Flags renamed NetSupport RAT client32.exe launches on Windows using a specific Imphash and file metadata, while filtering a matching image path.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-09-19
Updated
2026-07-30

What it detects

This rule identifies execution events where process metadata indicates NetSupport Remote Control and an original file name containing client32.exe. It keys off a specific Imphash value along with Product and OriginalFileName strings, and then excludes cases where the Image path ends with \client32.exe. The behavior matters because attackers may rename or masquerade known RAT binaries to evade simpler filename-based detections; the rule relies on process creation telemetry with hash, product, original file name, and image path fields.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.