PUA - System Informer Execution
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "Process started" AND PROCESSNAME endswith "\SystemInformer.exe" OR ORIGINALFILENAME = "SystemInformer.exe" OR MESSAGE = "System Informer" OR PRODUCT_NAME = "System Informer" OR HASHES contains "MD5=19426363A37C03C3ED6FEDF57B6696EC,SHA1=8B12C6DA8FAC0D5E8AB999C31E5EA04AF32D53DC,SHA256=8EE9D84DE50803545937A63C686822388A3338497CDDB660D5D69CF68B68F287,IMPHASH=B68908ADAEB5D662F87F2528AF318F12" select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Florian Roth (Nextron Systems)


