Windows Process Creation: Crassus Privilege Escalation Discovery Tool Execution

Identifies execution of the Crassus Windows privilege escalation discovery tool via process metadata.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
pH-T (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-17
Updated
2026-07-30

ATT&CK techniques

Recon
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process creation events where the executable path ends with Crassus.exe, the original file name is Crassus.exe, or the process description contains the string "Crassus". Crassus is used to discover Windows privilege escalation opportunities, which can precede further exploitation. The detection relies on process creation telemetry that includes image path, OriginalFileName, and Description metadata from Windows.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.