Security Privileges Enumeration Via Whoami.EXE

 Original Source: [Sigma source]
Title: Security Privileges Enumeration Via Whoami.EXE
Status: test
Description:Detects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privileges. This is often used after a privilege escalation attempt.
References:
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/whoami
Author: Florian Roth (Nextron Systems)
Date: 2021-05-05
modified:2023-02-28
Tags:
  • -'attack.privilege-escalation'
  • -'attack.discovery'
  • -'attack.t1033'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\whoami.exe' OriginalFileName:'whoami.exe'   selection_cli:
    CommandLine|contains:
      -' /priv'
      -' -priv'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high