Detection rules › Sigma

HKTL - SharpSuccessor Privilege Escalation Tool Execution

Status
experimental
Severity
high
Log source
category process_creation, product windows
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects the execution of SharpSuccessor, a tool used to exploit the BadSuccessor attack for privilege escalation in WinServer 2025 Active Directory environments. Successful usage of this tool can let the attackers gain the domain admin privileges by exploiting the BadSuccessor vulnerability.

MITRE ATT&CK coverage

TacticTechniques
Privilege Escalation

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 1: Process creation

Rule body

title: HKTL - SharpSuccessor Privilege Escalation Tool Execution
id: 38a1ac5f-9c74-47d2-a345-dd6f5eb4e7c8
status: experimental
description: |
    Detects the execution of SharpSuccessor, a tool used to exploit the BadSuccessor attack for privilege escalation in WinServer 2025 Active Directory environments.
    Successful usage of this tool can let the attackers gain the domain admin privileges by exploiting the BadSuccessor vulnerability.
references:
    - https://github.com/logangoins/SharpSuccessor
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-06-06
tags:
    - attack.privilege-escalation
    - attack.t1068
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        - Image|endswith: '\SharpSuccessor.exe'
        - OriginalFileName: 'SharpSuccessor.exe'
        - CommandLine|contains: 'SharpSuccessor'
        - CommandLine|contains|all:
              - ' add '
              - ' /impersonate'
              - ' /path'
              - ' /account'
              - ' /name'
    condition: selection
falsepositives:
    - Unknown
level: high

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    - Image|endswith: '\SharpSuccessor.exe'
    - OriginalFileName: 'SharpSuccessor.exe'
    - CommandLine|contains: 'SharpSuccessor'
    - CommandLine|contains|all:
          - ' add '
          - ' /impersonate'
          - ' /path'
          - ' /account'
          - ' /name'

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • /account
  • /impersonate
  • /name
  • /path
  • add corpus 15 (sigma 13, splunk 1, chronicle 1)
  • SharpSuccessor
field:"CommandLine" kind:match
Imageends_with
  • \SharpSuccessor.exe
field:"Image" kind:ends_with value:"\SharpSuccessor.exe"
OriginalFileNameeq
  • SharpSuccessor.exe
field:"OriginalFileName" kind:eq value:"SharpSuccessor.exe"