This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Impersonate Execution
Original Source:
[Sigma source]
Title:
HackTool - Impersonate Execution
Status:
test
Description:
Detects execution of the Impersonate tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
References:
-https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/
-https://github.com/sensepost/impersonate
Author:
Sai Prashanth Pulisetti @pulisettis
Date:
2022-12-21
modified:
2024-11-23
Tags:
-'attack.privilege-escalation'
-'attack.stealth'
-'attack.t1134.001'
-'attack.t1134.003'
Logsource:
product: windows
category: process_creation
Detection:
selection_commandline_exe:
CommandLine|contains
:
'impersonate.exe'
selection_commandline_opt:
CommandLine|contains
:
-' list '
-' exec '
-' adduser '
selection_hash:
Hashes|contains
:
-'MD5=9520714AB576B0ED01D1513691377D01'
-'SHA256=E81CC96E2118DC4FBFE5BAD1604E0AC7681960143E2101E1A024D52264BB0A8A'
-'IMPHASH=0A358FFC1697B7A07D0E817AC740DF62'
condition
:
all of selection_commandline_* or selection_hash
Falsepositives:
-Unknown
Level:
medium