Windows Process Creation: GMER Rootkit Tool Execution (gmer.exe)

Flags execution of gmer.exe on Windows when matched by known process hashes.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-10-05
Updated
2026-07-31

What it detects

This rule identifies execution of the GMER rootkit tool by matching process image paths that end with \gmer.exe and confirming the binary using specific hash values. Attackers may use GMER-like tooling to enumerate or assess rootkit presence, which can indicate stealth-focused activity. It relies on Windows process creation telemetry and available image path and hash fields to correlate the executable.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.