Windows execution of UACMe (Akagi.exe/Akagi64.exe) via PE metadata indicators
Flags Windows processes likely running UACMe (Akagi.exe/Akagi64.exe) using PE metadata and known IMPHASH indicators.
FreeUnreviewedSigmahighv1
windows-execution-of-uacme-akagi-exe-akagi64-exe-via-pe-metadata-indicators-d38d2fa4
title: Windows execution of UACMe (Akagi.exe/Akagi64.exe) via PE metadata indicators
id: b5e7d8d6-c363-4615-8a6b-451284b6649f
status: test
description: This rule identifies execution of the UACMe tool by matching process creation telemetry against specific PE metadata values, including product/company/description fields and original file names for Akagi.exe or Akagi64.exe. It matters because UACMe is used to bypass Windows UAC as part of privilege escalation activity. The detection relies on process creation events that include PE image metadata and, optionally, Sysmon image hash fields containing known IMPHASH values.
references:
- https://github.com/hfiref0x/UACME
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_uacme.yml
author: Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule Team
date: 2021-08-30
modified: 2024-11-23
tags:
- attack.privilege-escalation
- attack.t1548.002
logsource:
category: process_creation
product: windows
detection:
selection_pe:
- Product: UACMe
- Company:
- REvol Corp
- APT 92
- UG North
- Hazardous Environments
- CD Project Rekt
- Description:
- UACMe main module
- Pentesting utility
- OriginalFileName:
- Akagi.exe
- Akagi64.exe
selection_img:
Image|endswith:
- \Akagi64.exe
- \Akagi.exe
selection_hashes_sysmon:
Hashes|contains:
- IMPHASH=767637C23BB42CD5D7397CF58B0BE688
- IMPHASH=14C4E4C72BA075E9069EE67F39188AD8
- IMPHASH=3C782813D4AFCE07BBFC5A9772ACDBDC
- IMPHASH=7D010C6BB6A3726F327F7E239166D127
- IMPHASH=89159BA4DD04E4CE5559F132A9964EB3
- IMPHASH=6F33F4A5FC42B8CEC7314947BD13F30F
- IMPHASH=5834ED4291BDEB928270428EBBAF7604
- IMPHASH=5A8A8A43F25485E7EE1B201EDCBC7A38
- IMPHASH=DC7D30B90B2D8ABF664FBED2B1B59894
- IMPHASH=41923EA1F824FE63EA5BEB84DB7A3E74
- IMPHASH=3DE09703C8E79ED2CA3F01074719906B
condition: 1 of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: d38d2fa4-98e6-4a24-aff1-410b0c9ad177
type: derived
What it detects
This rule identifies execution of the UACMe tool by matching process creation telemetry against specific PE metadata values, including product/company/description fields and original file names for Akagi.exe or Akagi64.exe. It matters because UACMe is used to bypass Windows UAC as part of privilege escalation activity. The detection relies on process creation events that include PE image metadata and, optionally, Sysmon image hash fields containing known IMPHASH values.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.