PUA - System Informer Execution

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Process started" AND PROCESSNAME endswith "\SystemInformer.exe" OR ORIGINALFILENAME = "SystemInformer.exe" OR MESSAGE = "System Informer" OR PRODUCT_NAME = "System Informer" OR HASHES contains "MD5=19426363A37C03C3ED6FEDF57B6696EC,SHA1=8B12C6DA8FAC0D5E8AB999C31E5EA04AF32D53DC,SHA256=8EE9D84DE50803545937A63C686822388A3338497CDDB660D5D69CF68B68F287,IMPHASH=B68908ADAEB5D662F87F2528AF318F12" select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

Florian Roth (Nextron Systems)