Whoami.EXE Execution From Privileged Process

 Original Source: [Sigma source]
Title: Whoami.EXE Execution From Privileged Process
Status: test
Description:Detects the execution of "whoami.exe" by privileged accounts that are often abused by threat actors
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
  -https://web.archive.org/web/20221019044836/https://nsudo.m2team.org/en-us/
Author: Florian Roth (Nextron Systems), Teymur Kheirkhabarov
Date: 2022-01-28
modified:2023-12-04
Tags:
  • -'attack.privilege-escalation'
  • -'attack.discovery'
  • -'attack.t1033'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
OriginalFileName:'whoami.exe' Image|endswith:'\whoami.exe'   selection_user:
    User|contains:
      -'AUTHORI'
      -'AUTORI'
      -'TrustedInstaller'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high