Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Flags Windows execution of PCHunter64/32.exe using image path plus PE metadata and known hashes.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems), Nasreddine Bencherchali (SigmaHQ), DRL 1.1
- Published
- 2022-10-10
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags execution of the PCHunter utility on Windows by matching the process image name ending with PCHunter64.exe or PCHunter32.exe, along with specific file metadata (OriginalFileName and description) and known hashes. Attackers may use PCHunter-like tooling to inspect and manipulate process and kernel-related behavior as part of discovery or system interaction. The detection relies on process creation telemetry including the executable path, file properties, and hash values.
Reporting behind it
- web.archive.orghttps://web.archive.org/web/20231210115125/http://www.xuetr.com/
- crowdstrike.comhttps://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/
- hexacorn.comhttps://www.hexacorn.com/blog/2018/04/20/kernel-hacking-tool-you-might-have-never-heard-of-xuetr-pchunter/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_pchunter.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
id: 34fff399-15c1-4907-ad95-0f549d74e841
status: test
description: This rule flags execution of the PCHunter utility on Windows by matching the process image name ending with PCHunter64.exe or PCHunter32.exe, along with specific file metadata (OriginalFileName and description) and known hashes. Attackers may use PCHunter-like tooling to inspect and manipulate process and kernel-related behavior as part of discovery or system interaction. The detection relies on process creation telemetry including the executable path, file properties, and hash values.
references:
- https://web.archive.org/web/20231210115125/http://www.xuetr.com/
- https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/
- https://www.hexacorn.com/blog/2018/04/20/kernel-hacking-tool-you-might-have-never-heard-of-xuetr-pchunter/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_pchunter.yml
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule Team
date: 2022-10-10
modified: 2024-11-23
tags:
- attack.execution
- attack.discovery
- attack.t1082
- attack.t1057
- attack.t1012
- attack.t1083
- attack.t1007
logsource:
category: process_creation
product: windows
detection:
selection_image:
Image|endswith:
- \PCHunter64.exe
- \PCHunter32.exe
selection_pe:
- OriginalFileName: PCHunter.exe
- Description: Epoolsoft Windows Information View Tools
selection_hashes:
Hashes|contains:
- SHA1=5F1CBC3D99558307BC1250D084FA968521482025
- MD5=987B65CD9B9F4E9A1AFD8F8B48CF64A7
- SHA256=2B214BDDAAB130C274DE6204AF6DBA5AEEC7433DA99AA950022FA306421A6D32
- IMPHASH=444D210CEA1FF8112F256A4997EED7FF
- SHA1=3FB89787CB97D902780DA080545584D97FB1C2EB
- MD5=228DD0C2E6287547E26FFBD973A40F14
- SHA256=55F041BF4E78E9BFA6D4EE68BE40E496CE3A1353E1CA4306598589E19802522C
- IMPHASH=0479F44DF47CFA2EF1CCC4416A538663
condition: 1 of selection_*
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: fca949cc-79ca-446e-8064-01aa7e52ece5
type: derived