Lsass Memory Dump via Comsvcs DLL

 Original Source: [Sigma source]
Title: Lsass Memory Dump via Comsvcs DLL
Status: test
Description:Detects adversaries leveraging the MiniDump export function from comsvcs.dll via rundll32 to perform a memory dump from lsass.
References:
  -https://twitter.com/shantanukhande/status/1229348874298388484
  -https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Date: 2020-10-20
modified:2023-11-29
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    TargetImage|endswith: '\lsass.exe'
    SourceImage|endswith: '\rundll32.exe'
    CallTrace|contains: 'comsvcs.dll'
  condition:selection
Falsepositives:
  -Unknown
Level: high