Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)

Flags Windows execution of PCHunter64/32.exe using image path plus PE metadata and known hashes.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (SigmaHQ), DRL 1.1
Published
2022-10-10
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags execution of the PCHunter utility on Windows by matching the process image name ending with PCHunter64.exe or PCHunter32.exe, along with specific file metadata (OriginalFileName and description) and known hashes. Attackers may use PCHunter-like tooling to inspect and manipulate process and kernel-related behavior as part of discovery or system interaction. The detection relies on process creation telemetry including the executable path, file properties, and hash values.

Related detections9 linkedT1082 — drag to rearrange
Cisco AAA discovery via show/dir commands
Linux sysinfo Syscall for System Information Discovery
PowerShell Registry Reconnaissance Indicators on Windows via Script Block Logging
Windows reg.exe Registry Query Reconnaissance (Process Creation)
Suspicious System Profiler Hardware Enumeration (via process_creation)
Antivirus Software Discovery via tasklist and findstr
Registry Query for WDigest
Suspicious Hardware Inventory Discovery via WMIC Device Class Queries (via process_creation)
Suspicious macOS Hardware Identifier Reconnaissance via ioreg (via process_creation)
Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Pivot detection · T1082 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.