Windows Process Hacker Execution Identified by Image Metadata and Hashes

Alerts on Process Hacker being executed on Windows when process creation metadata or hashes match known indicators.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-10-10
Updated
2026-07-30

ATT&CK techniques

Persistence → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags Windows process executions where the executable image and related metadata match Process Hacker indicators, including path/name patterns, original file name, product/description strings, and specific file hashes or imp hashes. Process Hacker is commonly abused to inspect or manipulate system processes and low-level settings, making its execution a useful signal for attacker activity. Telemetry relied on includes process creation events with file path, image metadata (original file name, product, description), and hash/imphash values.

Related detections9 linkedT1543 — drag to rearrange
System Informer Execution on Windows Process Creation
Malicious BRICKSTORM Backdoor Execution via Masqueraded Binary Path
Suspicious Windows Security Spoofing via pin Executable Writing output.txt via process_creation
Obfuscated Extended Rights Backdoor Obfuscation - Via localizationDisplayId Attribute (via security)
Suspicious Process Execution from Public User Media Folders via process_creation
Suspicious Windows Sandbox Configuration Execution for AsyncRAT via Process Creation
Suspicious SonicWall SMA init.d Persistence Launching deploy_new.py
Malicious Linux XorDDoS gcc.pid Device Marker File via file_event
Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Windows Process Hacker Execution Identified by Image Metadata and Hashes
Pivot detection · T1543 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.