Windows Process Hacker Execution Identified by Image Metadata and Hashes
Alerts on Process Hacker being executed on Windows when process creation metadata or hashes match known indicators.
FreeUnreviewedSigmamediumv1
windows-process-hacker-execution-identified-by-image-metadata-and-hashes-811e0002
title: Windows Process Hacker Execution Identified by Image Metadata and Hashes
id: 24cddd36-17d6-4699-aff6-97a93f733428
related:
- id: 5722dff1-4bdd-4949-86ab-fbaf707e767a
type: similar
- id: 811e0002-b13b-4a15-9d00-a613fce66e42
type: derived
status: test
description: This rule flags Windows process executions where the executable image and related metadata match Process Hacker indicators, including path/name patterns, original file name, product/description strings, and specific file hashes or imp hashes. Process Hacker is commonly abused to inspect or manipulate system processes and low-level settings, making its execution a useful signal for attacker activity. Telemetry relied on includes process creation events with file path, image metadata (original file name, product, description), and hash/imphash values.
references:
- https://processhacker.sourceforge.io/
- https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_pua_process_hacker.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-10-10
modified: 2024-11-23
tags:
- attack.discovery
- attack.persistence
- attack.privilege-escalation
- attack.stealth
- attack.t1622
- attack.t1564
- attack.t1543
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|contains: \ProcessHacker_
- Image|endswith: \ProcessHacker.exe
- OriginalFileName:
- ProcessHacker.exe
- Process Hacker
- Description: Process Hacker
- Product: Process Hacker
- Hashes|contains:
- MD5=68F9B52895F4D34E74112F3129B3B00D
- MD5=B365AF317AE730A67C936F21432B9C71
- SHA1=A0BDFAC3CE1880B32FF9B696458327CE352E3B1D
- SHA1=C5E2018BF7C0F314FED4FD7FE7E69FA2E648359E
- SHA256=D4A0FE56316A2C45B9BA9AC1005363309A3EDC7ACF9E4DF64D326A0FF273E80F
- SHA256=BD2C2CF0631D881ED382817AFCCE2B093F4E412FFB170A719E2762F250ABFEA4
- IMPHASH=3695333C60DEDECDCAFF1590409AA462
- IMPHASH=04DE0AD9C37EB7BD52043D2ECAC958DF
condition: selection
falsepositives:
- While sometimes 'Process Hacker is used by legitimate administrators, the execution of Process Hacker must be investigated and allowed on a case by case basis
level: medium
license: DRL-1.1
What it detects
This rule flags Windows process executions where the executable image and related metadata match Process Hacker indicators, including path/name patterns, original file name, product/description strings, and specific file hashes or imp hashes. Process Hacker is commonly abused to inspect or manipulate system processes and low-level settings, making its execution a useful signal for attacker activity. Telemetry relied on includes process creation events with file path, image metadata (original file name, product, description), and hash/imphash values.
Known false positives
- While sometimes 'Process Hacker is used by legitimate administrators, the execution of Process Hacker must be investigated and allowed on a case by case basis
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.