Windows Process Creation: Impersonate.exe HackTool Execution
Flags execution of impersonate.exe (Impersonate tool) on Windows using command-line subcommands or known hashes.
FreeUnreviewedSigmamediumv1
windows-process-creation-impersonate-exe-hacktool-execution-cf0c254b
title: "Windows Process Creation: Impersonate.exe HackTool Execution"
id: b8636b81-b6f1-4c94-8ad4-19b4c01c4177
status: test
description: This rule identifies execution of the Impersonate tool by matching process command lines that reference impersonate.exe and specific subcommands (list, exec, adduser), or by correlating with known file hashes. Attackers can use this tool to manipulate Windows tokens to support remote or interactive compromise paths. Telemetry relies on Windows process creation data, including CommandLine and file Hashes (MD5, SHA256, or IMPHASH).
references:
- https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/
- https://github.com/sensepost/impersonate
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_impersonate.yml
author: Sai Prashanth Pulisetti @pulisettis, Huntrule Team
date: 2022-12-21
modified: 2024-11-23
tags:
- attack.privilege-escalation
- attack.stealth
- attack.t1134.001
- attack.t1134.003
logsource:
product: windows
category: process_creation
detection:
selection_commandline_exe:
CommandLine|contains: impersonate.exe
selection_commandline_opt:
CommandLine|contains:
- " list "
- " exec "
- " adduser "
selection_hash:
Hashes|contains:
- MD5=9520714AB576B0ED01D1513691377D01
- SHA256=E81CC96E2118DC4FBFE5BAD1604E0AC7681960143E2101E1A024D52264BB0A8A
- IMPHASH=0A358FFC1697B7A07D0E817AC740DF62
condition: all of selection_commandline_* or selection_hash
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: cf0c254b-22f1-4b2b-8221-e137b3c0af94
type: derived
What it detects
This rule identifies execution of the Impersonate tool by matching process command lines that reference impersonate.exe and specific subcommands (list, exec, adduser), or by correlating with known file hashes. Attackers can use this tool to manipulate Windows tokens to support remote or interactive compromise paths. Telemetry relies on Windows process creation data, including CommandLine and file Hashes (MD5, SHA256, or IMPHASH).
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.