This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
LSASS Process Memory Dump Files
Original Source:
[Sigma source]
Title:
LSASS Process Memory Dump Files
Status:
test
Description:
Detects creation of files with names used by different memory dumping tools to create a memory dump of the LSASS process memory, which contains user credentials.
References:
-https://www.google.com/search?q=procdump+lsass
-https://medium.com/@markmotig/some-ways-to-dump-lsass-exe-c4a75fdc49bf
-https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/credential_access_lsass_memdump_file_created.toml
-https://www.whiteoaksecurity.com/blog/attacks-defenses-dumping-lsass-no-mimikatz/
-https://github.com/helpsystems/nanodump
-https://github.com/CCob/MirrorDump
-https://github.com/safedv/RustiveDump/blob/1a9b026b477587becfb62df9677cede619d42030/src/main.rs#L35
-https://github.com/ricardojoserf/NativeDump/blob/01d8cd17f31f51f5955a38e85cd3c83a17596175/NativeDump/Program.cs#L258
Author:
Florian Roth (Nextron Systems)
Date:
2021-11-15
modified:
2024-10-08
Tags:
-'attack.credential-access'
-'attack.t1003.001'
Logsource:
product: windows
category: file_event
Detection:
selection_1:
TargetFilename|endswith
:
-'\Andrew.dmp'
-'\Coredump.dmp'
-'\lsass.dmp'
-'\lsass.rar'
-'\lsass.zip'
-'\NotLSASS.zip'
-'\PPLBlade.dmp'
-'\rustive.dmp'
selection_2:
TargetFilename|contains
:
-'\lsass_2'
-'\lsassdmp'
-'\lsassdump'
selection_3:
TargetFilename|contains|all
:
-'\lsass'
-'.dmp'
selection_4:
TargetFilename|contains
:
'SQLDmpr'
TargetFilename|endswith
:
'.mdmp'
selection_5:
TargetFilename|contains
:
-'\nanodump'
-'\proc_'
TargetFilename|endswith
:
'.dmp'
condition
:
1 of selection_*
Falsepositives:
-Unknown
Level:
high