Windows Process Creation: Impersonate.exe HackTool Execution

Flags execution of impersonate.exe (Impersonate tool) on Windows using command-line subcommands or known hashes.

FreeUnreviewedSigmamediumv1
title: "Windows Process Creation: Impersonate.exe HackTool Execution"
id: b8636b81-b6f1-4c94-8ad4-19b4c01c4177
status: test
description: This rule identifies execution of the Impersonate tool by matching process command lines that reference impersonate.exe and specific subcommands (list, exec, adduser), or by correlating with known file hashes. Attackers can use this tool to manipulate Windows tokens to support remote or interactive compromise paths. Telemetry relies on Windows process creation data, including CommandLine and file Hashes (MD5, SHA256, or IMPHASH).
references:
  - https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/
  - https://github.com/sensepost/impersonate
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_impersonate.yml
author: Sai Prashanth Pulisetti @pulisettis, Huntrule Team
date: 2022-12-21
modified: 2024-11-23
tags:
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1134.001
  - attack.t1134.003
logsource:
  product: windows
  category: process_creation
detection:
  selection_commandline_exe:
    CommandLine|contains: impersonate.exe
  selection_commandline_opt:
    CommandLine|contains:
      - " list "
      - " exec "
      - " adduser "
  selection_hash:
    Hashes|contains:
      - MD5=9520714AB576B0ED01D1513691377D01
      - SHA256=E81CC96E2118DC4FBFE5BAD1604E0AC7681960143E2101E1A024D52264BB0A8A
      - IMPHASH=0A358FFC1697B7A07D0E817AC740DF62
  condition: all of selection_commandline_* or selection_hash
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: cf0c254b-22f1-4b2b-8221-e137b3c0af94
    type: derived

What it detects

This rule identifies execution of the Impersonate tool by matching process command lines that reference impersonate.exe and specific subcommands (list, exec, adduser), or by correlating with known file hashes. Attackers can use this tool to manipulate Windows tokens to support remote or interactive compromise paths. Telemetry relies on Windows process creation data, including CommandLine and file Hashes (MD5, SHA256, or IMPHASH).

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.