Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

8Base – Rootkit-Capable Process/Driver Killers (GMER, PCHunter, Process Hacker)

8base Defense Evasion Sentinel
MITRE ATT&CK
Service Stop
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (8base)
What This Detects
8Base's toolkit leans on GMER, PCHunter and Process Hacker – rootkit-detection tools repurposed to identify and kill AV/EDR processes. Any of these on an endpoint outside an IR/forensics context is worth reviewing.
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName in~ ("gmer.exe","pchunter64.exe","pchunter32.exe","processhacker.exe")
| project Timestamp, DeviceName, FileName, FolderPath, ProcessCommandLine, AccountName, InitiatingProcessFileName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.