Windows Process Hacker Execution Identified by Image Metadata and Hashes
Alerts on Process Hacker being executed on Windows when process creation metadata or hashes match known indicators.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-10-10
- Updated
- 2026-07-30
ATT&CK techniques
Persistence → DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows process executions where the executable image and related metadata match Process Hacker indicators, including path/name patterns, original file name, product/description strings, and specific file hashes or imp hashes. Process Hacker is commonly abused to inspect or manipulate system processes and low-level settings, making its execution a useful signal for attacker activity. Telemetry relied on includes process creation events with file path, image metadata (original file name, product, description), and hash/imphash values.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Process Hacker Execution Identified by Image Metadata and Hashes
id: 24cddd36-17d6-4699-aff6-97a93f733428
related:
- id: 5722dff1-4bdd-4949-86ab-fbaf707e767a
type: similar
- id: 811e0002-b13b-4a15-9d00-a613fce66e42
type: derived
status: test
description: This rule flags Windows process executions where the executable image and related metadata match Process Hacker indicators, including path/name patterns, original file name, product/description strings, and specific file hashes or imp hashes. Process Hacker is commonly abused to inspect or manipulate system processes and low-level settings, making its execution a useful signal for attacker activity. Telemetry relied on includes process creation events with file path, image metadata (original file name, product, description), and hash/imphash values.
references:
- https://processhacker.sourceforge.io/
- https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_pua_process_hacker.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-10-10
modified: 2024-11-23
tags:
- attack.discovery
- attack.persistence
- attack.privilege-escalation
- attack.stealth
- attack.t1622
- attack.t1564
- attack.t1543
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|contains: \ProcessHacker_
- Image|endswith: \ProcessHacker.exe
- OriginalFileName:
- ProcessHacker.exe
- Process Hacker
- Description: Process Hacker
- Product: Process Hacker
- Hashes|contains:
- MD5=68F9B52895F4D34E74112F3129B3B00D
- MD5=B365AF317AE730A67C936F21432B9C71
- SHA1=A0BDFAC3CE1880B32FF9B696458327CE352E3B1D
- SHA1=C5E2018BF7C0F314FED4FD7FE7E69FA2E648359E
- SHA256=D4A0FE56316A2C45B9BA9AC1005363309A3EDC7ACF9E4DF64D326A0FF273E80F
- SHA256=BD2C2CF0631D881ED382817AFCCE2B093F4E412FFB170A719E2762F250ABFEA4
- IMPHASH=3695333C60DEDECDCAFF1590409AA462
- IMPHASH=04DE0AD9C37EB7BD52043D2ECAC958DF
condition: selection
falsepositives:
- While sometimes 'Process Hacker is used by legitimate administrators, the execution of Process Hacker must be investigated and allowed on a case by case basis
level: medium
license: DRL-1.1