Windows execution of LocalPotato POC (LocalPotato.exe with specific PE/CLI traits)

Detects LocalPotato.exe process execution on Windows using image path, typical CLI parameters, and known imphash values.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-02-14
Updated
2026-07-31

What it detects

This rule identifies execution attempts of the LocalPotato Proof of Concept on Windows by matching process creation events for LocalPotato.exe alongside indicative command-line arguments. It also uses embedded PE metadata (imphash values) to reduce false positives. Attackers may use LocalPotato to attempt local privilege escalation, so correlating image path, command line, and hash metadata is key telemetry for detection.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.