Windows Process Hacker Execution Identified by Image Metadata and Hashes

Alerts on Process Hacker being executed on Windows when process creation metadata or hashes match known indicators.

FreeUnreviewedSigmamediumv1
title: Windows Process Hacker Execution Identified by Image Metadata and Hashes
id: 24cddd36-17d6-4699-aff6-97a93f733428
related:
  - id: 5722dff1-4bdd-4949-86ab-fbaf707e767a
    type: similar
  - id: 811e0002-b13b-4a15-9d00-a613fce66e42
    type: derived
status: test
description: This rule flags Windows process executions where the executable image and related metadata match Process Hacker indicators, including path/name patterns, original file name, product/description strings, and specific file hashes or imp hashes. Process Hacker is commonly abused to inspect or manipulate system processes and low-level settings, making its execution a useful signal for attacker activity. Telemetry relied on includes process creation events with file path, image metadata (original file name, product, description), and hash/imphash values.
references:
  - https://processhacker.sourceforge.io/
  - https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_pua_process_hacker.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-10-10
modified: 2024-11-23
tags:
  - attack.discovery
  - attack.persistence
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1622
  - attack.t1564
  - attack.t1543
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Image|contains: \ProcessHacker_
    - Image|endswith: \ProcessHacker.exe
    - OriginalFileName:
        - ProcessHacker.exe
        - Process Hacker
    - Description: Process Hacker
    - Product: Process Hacker
    - Hashes|contains:
        - MD5=68F9B52895F4D34E74112F3129B3B00D
        - MD5=B365AF317AE730A67C936F21432B9C71
        - SHA1=A0BDFAC3CE1880B32FF9B696458327CE352E3B1D
        - SHA1=C5E2018BF7C0F314FED4FD7FE7E69FA2E648359E
        - SHA256=D4A0FE56316A2C45B9BA9AC1005363309A3EDC7ACF9E4DF64D326A0FF273E80F
        - SHA256=BD2C2CF0631D881ED382817AFCCE2B093F4E412FFB170A719E2762F250ABFEA4
        - IMPHASH=3695333C60DEDECDCAFF1590409AA462
        - IMPHASH=04DE0AD9C37EB7BD52043D2ECAC958DF
  condition: selection
falsepositives:
  - While sometimes 'Process Hacker is used by legitimate administrators, the execution of Process Hacker must be investigated and allowed on a case by case basis
level: medium
license: DRL-1.1

What it detects

This rule flags Windows process executions where the executable image and related metadata match Process Hacker indicators, including path/name patterns, original file name, product/description strings, and specific file hashes or imp hashes. Process Hacker is commonly abused to inspect or manipulate system processes and low-level settings, making its execution a useful signal for attacker activity. Telemetry relied on includes process creation events with file path, image metadata (original file name, product, description), and hash/imphash values.

Known false positives

  • While sometimes 'Process Hacker is used by legitimate administrators, the execution of Process Hacker must be investigated and allowed on a case by case basis

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.