ProcessHacker Privilege Elevation

 Original Source: [Sigma source]
Title: ProcessHacker Privilege Elevation
Status: test
Description:Detects a ProcessHacker tool that elevated privileges to a very high level
References:
  -https://twitter.com/1kwpeter/status/1397816101455765504
Author: Florian Roth (Nextron Systems)
Date: 2021-05-27
modified:2022-12-25
Tags:
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.t1543.003'
  • -'attack.t1569.002'
Logsource:
  • product: windows
  • service: system
Detection:
  selection:
    Provider_Name: 'Service Control Manager'
    EventID: '7045'
    ServiceName|startswith: 'ProcessHacker'
    AccountName: 'LocalSystem'
  condition:selection
Falsepositives:
  -Unlikely
Level: high