PUA - System Informer Execution

 Original Source: [Sigma source]
Title: PUA - System Informer Execution
Status: test
Description:Detects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations
References:
  -https://github.com/winsiderss/systeminformer
Author: Florian Roth (Nextron Systems)
Date: 2023-05-08
modified:2024-11-23
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.discovery'
  • -'attack.stealth'
  • -'attack.t1082'
  • -'attack.t1564'
  • -'attack.t1543'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Image|endswith:'\SystemInformer.exe' OriginalFileName:'SystemInformer.exe' Description:'System Informer' Product:'System Informer'     - Hashes|contains:
      - 'MD5=19426363A37C03C3ED6FEDF57B6696EC'
      - 'SHA1=8B12C6DA8FAC0D5E8AB999C31E5EA04AF32D53DC'
      - 'SHA256=8EE9D84DE50803545937A63C686822388A3338497CDDB660D5D69CF68B68F287'
      - 'IMPHASH=B68908ADAEB5D662F87F2528AF318F12'
  condition:selection
Falsepositives:
  -System Informer is regularly used legitimately by system administrators or developers. Apply additional filters accordingly
Level: medium