HackTool - HandleKatz Duplicating LSASS Handle

 Original Source: [Sigma source]
Title: HackTool - HandleKatz Duplicating LSASS Handle
Status: test
Description:Detects HandleKatz opening LSASS to duplicate its handle to later dump the memory without opening any new handles
References:
  -https://github.com/codewhitesec/HandleKatz
Author: Bhabesh Raj (rule), @thefLinkk
Date: 2022-06-27
modified:2023-11-28
Tags:
  • -'attack.execution'
  • -'attack.t1106'
  • -'attack.t1003.001'
  • -'attack.credential-access'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    TargetImage|endswith: '\lsass.exe'
    GrantedAccess: '0x1440'
    CallTrace|startswith: 'C:\Windows\System32\ntdll.dll+'
    CallTrace|contains: '|UNKNOWN('
    CallTrace|endswith: ')'
  condition:selection
Falsepositives:
  -Unknown
Level: high