← Back to Explore
sigmahighHunting
HackTool - CoercedPotato Execution
Detects the use of CoercedPotato, a tool for privilege escalation
Detection Query
selection_loader_img:
Image|endswith: \CoercedPotato.exe
selection_params:
CommandLine|contains: " --exploitId "
selection_loader_imphash:
Hashes|contains:
- IMPHASH=A75D7669DB6B2E107A44C4057FF7F7D6
- IMPHASH=F91624350E2C678C5DCBE5E1F24E22C9
- IMPHASH=14C81850A079A87E83D50CA41C709A15
condition: 1 of selection_*
Author
Florian Roth (Nextron Systems)
Created
2023-10-11
Data Sources
windowsProcess Creation Events
Platforms
windows
References
Tags
attack.defense-evasionattack.privilege-escalationattack.t1055
Raw Content
title: HackTool - CoercedPotato Execution
id: e8d34729-86a4-4140-adfd-0a29c2106307
status: test
description: Detects the use of CoercedPotato, a tool for privilege escalation
references:
- https://github.com/hackvens/CoercedPotato
- https://blog.hackvens.fr/articles/CoercedPotato.html
author: Florian Roth (Nextron Systems)
date: 2023-10-11
modified: 2024-11-23
tags:
- attack.defense-evasion
- attack.privilege-escalation
- attack.t1055
logsource:
category: process_creation
product: windows
detection:
selection_loader_img:
Image|endswith: '\CoercedPotato.exe'
selection_params:
CommandLine|contains: ' --exploitId '
selection_loader_imphash:
Hashes|contains:
- 'IMPHASH=A75D7669DB6B2E107A44C4057FF7F7D6'
- 'IMPHASH=F91624350E2C678C5DCBE5E1F24E22C9'
- 'IMPHASH=14C81850A079A87E83D50CA41C709A15'
condition: 1 of selection_*
falsepositives:
- Unknown
level: high