Windows execution of UACMe (Akagi.exe/Akagi64.exe) via PE metadata indicators

Flags Windows processes likely running UACMe (Akagi.exe/Akagi64.exe) using PE metadata and known IMPHASH indicators.

FreeUnreviewedSigmahighv1
title: Windows execution of UACMe (Akagi.exe/Akagi64.exe) via PE metadata indicators
id: b5e7d8d6-c363-4615-8a6b-451284b6649f
status: test
description: This rule identifies execution of the UACMe tool by matching process creation telemetry against specific PE metadata values, including product/company/description fields and original file names for Akagi.exe or Akagi64.exe. It matters because UACMe is used to bypass Windows UAC as part of privilege escalation activity. The detection relies on process creation events that include PE image metadata and, optionally, Sysmon image hash fields containing known IMPHASH values.
references:
  - https://github.com/hfiref0x/UACME
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_uacme.yml
author: Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule Team
date: 2021-08-30
modified: 2024-11-23
tags:
  - attack.privilege-escalation
  - attack.t1548.002
logsource:
  category: process_creation
  product: windows
detection:
  selection_pe:
    - Product: UACMe
    - Company:
        - REvol Corp
        - APT 92
        - UG North
        - Hazardous Environments
        - CD Project Rekt
    - Description:
        - UACMe main module
        - Pentesting utility
    - OriginalFileName:
        - Akagi.exe
        - Akagi64.exe
  selection_img:
    Image|endswith:
      - \Akagi64.exe
      - \Akagi.exe
  selection_hashes_sysmon:
    Hashes|contains:
      - IMPHASH=767637C23BB42CD5D7397CF58B0BE688
      - IMPHASH=14C4E4C72BA075E9069EE67F39188AD8
      - IMPHASH=3C782813D4AFCE07BBFC5A9772ACDBDC
      - IMPHASH=7D010C6BB6A3726F327F7E239166D127
      - IMPHASH=89159BA4DD04E4CE5559F132A9964EB3
      - IMPHASH=6F33F4A5FC42B8CEC7314947BD13F30F
      - IMPHASH=5834ED4291BDEB928270428EBBAF7604
      - IMPHASH=5A8A8A43F25485E7EE1B201EDCBC7A38
      - IMPHASH=DC7D30B90B2D8ABF664FBED2B1B59894
      - IMPHASH=41923EA1F824FE63EA5BEB84DB7A3E74
      - IMPHASH=3DE09703C8E79ED2CA3F01074719906B
  condition: 1 of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: d38d2fa4-98e6-4a24-aff1-410b0c9ad177
    type: derived

What it detects

This rule identifies execution of the UACMe tool by matching process creation telemetry against specific PE metadata values, including product/company/description fields and original file names for Akagi.exe or Akagi64.exe. It matters because UACMe is used to bypass Windows UAC as part of privilege escalation activity. The detection relies on process creation events that include PE image metadata and, optionally, Sysmon image hash fields containing known IMPHASH values.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.