This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - SafetyKatz Dump Indicator
Original Source:
[Sigma source]
Title:
HackTool - SafetyKatz Dump Indicator
Status:
test
Description:
Detects default lsass dump filename generated by SafetyKatz.
References:
-https://github.com/GhostPack/SafetyKatz
-https://github.com/GhostPack/SafetyKatz/blob/715b311f76eb3a4c8d00a1bd29c6cd1899e450b7/SafetyKatz/Program.cs#L63
Author:
Markus Neis
Date:
2018-07-24
modified:
2024-06-27
Tags:
-'attack.credential-access'
-'attack.t1003.001'
Logsource:
category: file_event
product: windows
Detection:
selection:
TargetFilename|endswith
:
'\Temp\debug.bin'
condition
:
selection
Falsepositives:
-Rare legitimate files with similar filename structure
Level:
high