HackTool - Impersonate Execution

 Original Source: [Sigma source]
Title: HackTool - Impersonate Execution
Status: test
Description:Detects execution of the Impersonate tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
References:
  -https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/
  -https://github.com/sensepost/impersonate
Author: Sai Prashanth Pulisetti @pulisettis
Date: 2022-12-21
modified:2024-11-23
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1134.001'
  • -'attack.t1134.003'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_commandline_exe:
    CommandLine|contains: 'impersonate.exe'
  selection_commandline_opt:
    CommandLine|contains:
      -' list '
      -' exec '
      -' adduser '

  selection_hash:
    Hashes|contains:
      -'MD5=9520714AB576B0ED01D1513691377D01'
      -'SHA256=E81CC96E2118DC4FBFE5BAD1604E0AC7681960143E2101E1A024D52264BB0A8A'
      -'IMPHASH=0A358FFC1697B7A07D0E817AC740DF62'

  condition:all of selection_commandline_* or selection_hash
Falsepositives:
  -Unknown
Level: medium