Windows HackTool Process Access Alerts via Suspicious Source Image Names
Alerts on Windows process access events initiated by processes whose image names match common credential/dumping hack tools.
FreeUnreviewedSigmahighv1
windows-hacktool-process-access-alerts-via-suspicious-source-image-names-d0d2f720
title: Windows HackTool Process Access Alerts via Suspicious Source Image Names
id: d98a6506-777e-406d-9bd9-1eb8efd1dee8
status: test
description: This rule flags Windows process access events where the accessing process matches a list of known hack tool executable names or related filename patterns. Attackers use process access to read or tamper with other processes (for example, to collect credentials or enable credential dumping), so this activity is a strong indicator of malicious tooling. It relies on process access telemetry that records the SourceImage for the process requesting access to another process.
references:
- https://jsecurity101.medium.com/bypassing-access-mask-auditing-strategies-480fb641c158
- https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_access/proc_access_win_hktl_generic_access.yml
author: Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule Team
date: 2023-11-27
tags:
- attack.credential-access
- attack.t1003.001
- attack.s0002
logsource:
category: process_access
product: windows
detection:
selection:
- SourceImage|endswith:
- \Akagi.exe
- \Akagi64.exe
- \atexec_windows.exe
- \Certify.exe
- \Certipy.exe
- \CoercedPotato.exe
- \crackmapexec.exe
- \CreateMiniDump.exe
- \dcomexec_windows.exe
- \dpapi_windows.exe
- \findDelegation_windows.exe
- \GetADUsers_windows.exe
- \GetNPUsers_windows.exe
- \getPac_windows.exe
- \getST_windows.exe
- \getTGT_windows.exe
- \GetUserSPNs_windows.exe
- \gmer.exe
- \hashcat.exe
- \htran.exe
- \ifmap_windows.exe
- \impersonate.exe
- \Inveigh.exe
- \LocalPotato.exe
- \mimikatz_windows.exe
- \mimikatz.exe
- \netview_windows.exe
- \nmapAnswerMachine_windows.exe
- \opdump_windows.exe
- \PasswordDump.exe
- \Potato.exe
- \PowerTool.exe
- \PowerTool64.exe
- \psexec_windows.exe
- \PurpleSharp.exe
- \pypykatz.exe
- \QuarksPwDump.exe
- \rdp_check_windows.exe
- \Rubeus.exe
- \SafetyKatz.exe
- \sambaPipe_windows.exe
- \SelectMyParent.exe
- \SharpChisel.exe
- \SharPersist.exe
- \SharpEvtMute.exe
- \SharpImpersonation.exe
- \SharpLDAPmonitor.exe
- \SharpLdapWhoami.exe
- \SharpUp.exe
- \SharpView.exe
- \smbclient_windows.exe
- \smbserver_windows.exe
- \sniff_windows.exe
- \sniffer_windows.exe
- \split_windows.exe
- \SpoolSample.exe
- \Stracciatella.exe
- \SysmonEOP.exe
- \temp\rot.exe
- \ticketer_windows.exe
- \TruffleSnout.exe
- \winPEASany_ofs.exe
- \winPEASany.exe
- \winPEASx64_ofs.exe
- \winPEASx64.exe
- \winPEASx86_ofs.exe
- \winPEASx86.exe
- \xordump.exe
- SourceImage|contains:
- \goldenPac
- \just_dce_
- \karmaSMB
- \kintercept
- \LocalPotato
- \ntlmrelayx
- \rpcdump
- \samrdump
- \secretsdump
- \smbexec
- \smbrelayx
- \wmiexec
- \wmipersist
- HotPotato
- Juicy Potato
- JuicyPotato
- PetitPotam
- RottenPotato
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: d0d2f720-d14f-448d-8242-51ff396a334e
type: derived
What it detects
This rule flags Windows process access events where the accessing process matches a list of known hack tool executable names or related filename patterns. Attackers use process access to read or tamper with other processes (for example, to collect credentials or enable credential dumping), so this activity is a strong indicator of malicious tooling. It relies on process access telemetry that records the SourceImage for the process requesting access to another process.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.