Windows Process Creation: Impersonate.exe HackTool Execution
Flags execution of impersonate.exe (Impersonate tool) on Windows using command-line subcommands or known hashes.
- Product
- windows
- Category
- process_creation
- Author
- Sai Prashanth Pulisetti @pulisettis (SigmaHQ), DRL 1.1
- Published
- 2022-12-21
- Updated
- 2026-07-31
ATT&CK techniques
Priv Esc → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events where the command line contains impersonate.exe and also matches either specific usage arguments (list, exec, adduser) or one of the embedded hash indicators (MD5, SHA256, IMPHASH). Attackers may use Impersonate to manipulate Windows tokens either remotely via PsExec/WmiExec or interactively as part of privilege escalation and stealthy access. It relies on Windows process creation telemetry, including CommandLine and Hash fields.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Process Creation: Impersonate.exe HackTool Execution"
id: b8636b81-b6f1-4c94-8ad4-19b4c01c4177
status: test
description: This rule flags process creation events where the command line contains impersonate.exe and also matches either specific usage arguments (list, exec, adduser) or one of the embedded hash indicators (MD5, SHA256, IMPHASH). Attackers may use Impersonate to manipulate Windows tokens either remotely via PsExec/WmiExec or interactively as part of privilege escalation and stealthy access. It relies on Windows process creation telemetry, including CommandLine and Hash fields.
references:
- https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/
- https://github.com/sensepost/impersonate
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_impersonate.yml
author: Sai Prashanth Pulisetti @pulisettis, Huntrule Team
date: 2022-12-21
modified: 2024-11-23
tags:
- attack.privilege-escalation
- attack.stealth
- attack.t1134.001
- attack.t1134.003
logsource:
product: windows
category: process_creation
detection:
selection_commandline_exe:
CommandLine|contains: impersonate.exe
selection_commandline_opt:
CommandLine|contains:
- " list "
- " exec "
- " adduser "
selection_hash:
Hashes|contains:
- MD5=9520714AB576B0ED01D1513691377D01
- SHA256=E81CC96E2118DC4FBFE5BAD1604E0AC7681960143E2101E1A024D52264BB0A8A
- IMPHASH=0A358FFC1697B7A07D0E817AC740DF62
condition: all of selection_commandline_* or selection_hash
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: cf0c254b-22f1-4b2b-8221-e137b3c0af94
type: derived