Potential Credential Dumping Attempt Via PowerShell Remote Thread

 Original Source: [Sigma source]
Title: Potential Credential Dumping Attempt Via PowerShell Remote Thread
Status: test
Description:Detects remote thread creation by PowerShell processes into "lsass.exe"
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse
Author: oscd.community, Natalia Shornikova
Date: 2020-10-06
modified:2022-12-18
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • product: windows
  • category: create_remote_thread
Detection:
  selection:
    SourceImage|endswith:
      -'\powershell.exe'
      -'\pwsh.exe'

    TargetImage|endswith: '\lsass.exe'
  condition:selection
Falsepositives:
  -Unknown
Level: high