LSASS Memory Access by Tool With Dump Keyword In Name

 Original Source: [Sigma source]
Title: LSASS Memory Access by Tool With Dump Keyword In Name
Status: test
Description:Detects LSASS process access requests from a source process with the "dump" keyword in its image name.
References:
  -https://twitter.com/_xpn_/status/1491557187168178176
  -https://www.ired.team/offensive-security/credential-access-and-credential-dumping/dump-credentials-from-lsass-process-without-mimikatz
Author: Florian Roth (Nextron Systems)
Date: 2022-02-10
modified:2023-11-29
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
  • -'attack.s0002'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    TargetImage|endswith: '\lsass.exe'
    SourceImage|contains: 'dump'
    GrantedAccess|endswith:
      -'10'
      -'30'
      -'50'
      -'70'
      -'90'
      -'B0'
      -'D0'
      -'F0'
      -'18'
      -'38'
      -'58'
      -'78'
      -'98'
      -'B8'
      -'D8'
      -'F8'
      -'1A'
      -'3A'
      -'5A'
      -'7A'
      -'9A'
      -'BA'
      -'DA'
      -'FA'
      -'0x14C2'
      -'FF'

  condition:selection
Falsepositives:
  -Rare programs that contain the word dump in their name and access lsass
Level: high