70 lines
3.6 KiB
YAML
70 lines
3.6 KiB
YAML
title: Process Hacker and System Informer Driver Load
|
|
id: 67add051-9ee7-4ad3-93ba-42935615ae8d
|
|
status: experimental
|
|
description: Detects the load of drivers used by Process Hacker and System Informer
|
|
references:
|
|
- https://processhacker.sourceforge.io/
|
|
- https://systeminformer.sourceforge.io/
|
|
- https://github.com/winsiderss/systeminformer
|
|
author: Florian Roth
|
|
date: 2022/11/16
|
|
modified: 2022/12/30
|
|
tags:
|
|
- attack.privilege_escalation
|
|
- cve.2021.21551
|
|
- attack.t1543
|
|
logsource:
|
|
category: driver_load
|
|
product: windows
|
|
detection:
|
|
selection_image:
|
|
ImageLoaded|endswith:
|
|
- '\kprocesshacker.sys'
|
|
- '\SystemInformer.sys'
|
|
selection_processhack_sysmon:
|
|
Hashes|contains:
|
|
- 'IMPHASH=821D74031D3F625BCBD0DF08B70F1E77'
|
|
- 'IMPHASH=F86759BB4DE4320918615DC06E998A39'
|
|
- 'IMPHASH=0A64EEB85419257D0CE32BD5D55C3A18'
|
|
- 'IMPHASH=6E7B34DFC017700B1517B230DF6FF0D0'
|
|
selection_processhack_hashes:
|
|
Imphash:
|
|
- '821D74031D3F625BCBD0DF08B70F1E77'
|
|
- 'F86759BB4DE4320918615DC06E998A39'
|
|
- '0A64EEB85419257D0CE32BD5D55C3A18'
|
|
- '6E7B34DFC017700B1517B230DF6FF0D0'
|
|
selection_systeminformer_sysmon:
|
|
Hashes|contains:
|
|
- 'SHA256=8B9AD98944AC9886EA4CB07700E71B78BE4A2740934BB7E46CA3B56A7C59AD24'
|
|
- 'SHA256=A41348BEC147CA4D9EA2869817527EB5CEA2E20202AF599D2B30625433BCF454'
|
|
- 'SHA256=38EE0A88AF8535A11EFE8D8DA9C6812AA07067B75A64D99705A742589BDD846D'
|
|
- 'SHA256=A773891ACF203A7EB0C0D30942FB1347648F1CD918AE2BFD9A4857B4DCF5081B'
|
|
- 'SHA256=4C3B81AC88A987BBDF7D41FA0AECC2CEDF5B9BD2F45E7A21F376D05345FC211D'
|
|
- 'SHA256=3241BC14BEC51CE6A691B9A3562E5C1D52E9D057D27A3D67FD0B245C350B6D34'
|
|
- 'SHA256=047C42E9BBA28366868847C7DAFC1E043FB038C796422D37220493517D68EE89'
|
|
- 'SHA256=18931DC81E95D0020466FA091E16869DBE824E543A4C2C8FE644FA71A0F44FEB'
|
|
- 'SHA256=B4C2EF76C204273132FDE38F0DED641C2C5EE767652E64E4C4071A4A973B6C1B'
|
|
- 'SHA256=640954AFC268565F7DAA6E6F81A8EE05311E33E34332B501A3C3FE5B22ADEA97'
|
|
- 'SHA256=251BE949F662C838718F8AA0A5F8211FB90346D02BD63FF91E6B224E0E01B656'
|
|
- 'SHA256=E2606F272F7BA054DF16BE464FDA57211EF0D14A0D959F9C8DCB0575DF1186E4'
|
|
- 'SHA256=3A9E1D17BEEB514F1B9B3BACAEE7420285DE5CBDCE89C5319A992C6CBD1DE138'
|
|
selection_systeminformer_hashes:
|
|
sha256:
|
|
- '8b9ad98944ac9886ea4cb07700e71b78be4a2740934bb7e46ca3b56a7c59ad24'
|
|
- 'a41348bec147ca4d9ea2869817527eb5cea2e20202af599d2b30625433bcf454'
|
|
- '38ee0a88af8535a11efe8d8da9c6812aa07067b75a64d99705a742589bdd846d'
|
|
- 'a773891acf203a7eb0c0d30942fb1347648f1cd918ae2bfd9a4857b4dcf5081b'
|
|
- '4c3b81ac88a987bbdf7d41fa0aecc2cedf5b9bd2f45e7a21f376d05345fc211d'
|
|
- '3241bc14bec51ce6a691b9a3562e5c1d52e9d057d27a3d67fd0b245c350b6d34'
|
|
- '047c42e9bba28366868847c7dafc1e043fb038c796422d37220493517d68ee89'
|
|
- '18931dc81e95d0020466fa091e16869dbe824e543a4c2c8fe644fa71a0f44feb'
|
|
- 'b4c2ef76c204273132fde38f0ded641c2c5ee767652e64e4c4071a4a973b6c1b'
|
|
- '640954afc268565f7daa6e6f81a8ee05311e33e34332b501a3c3fe5b22adea97'
|
|
- '251be949f662c838718f8aa0a5f8211fb90346d02bd63ff91e6b224e0e01b656'
|
|
- 'e2606f272f7ba054df16be464fda57211ef0d14a0d959f9c8dcb0575df1186e4'
|
|
- '3a9e1d17beeb514f1b9b3bacaee7420285de5cbdce89c5319a992c6cbd1de138'
|
|
condition: 1 of selection*
|
|
falsepositives:
|
|
- Legitimate user of process hacker or system informer by low level developers or system administrators
|
|
level: medium
|