HackTool - SharpImpersonation Execution

 Original Source: [Sigma source]
Title: HackTool - SharpImpersonation Execution
Status: test
Description:Detects execution of the SharpImpersonation tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
References:
  -https://s3cur3th1ssh1t.github.io/SharpImpersonation-Introduction/
  -https://github.com/S3cur3Th1sSh1t/SharpImpersonation
Author: Sai Prashanth Pulisetti @pulisettis, Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-27
modified:2023-02-13
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1134.001'
  • -'attack.t1134.003'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\SharpImpersonation.exe' OriginalFileName:'SharpImpersonation.exe'   selection_cli:
    - CommandLine|contains|all:
      - ' user:'
      - ' binary:'
    - CommandLine|contains|all:
      - ' user:'
      - ' shellcode:'
    - CommandLine|contains:
      - ' technique:CreateProcessAsUserW'
      - ' technique:ImpersonateLoggedOnuser'
  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: high