Credential Dumping Activity By Python Based Tool

 Original Source: [Sigma source]
Title: Credential Dumping Activity By Python Based Tool
Status: stable
Description:Detects LSASS process access for potential credential dumping by a Python-like tool such as LaZagne or Pypykatz.
References:
  -https://twitter.com/bh4b3sh/status/1303674603819081728
  -https://github.com/skelsec/pypykatz
Author: Bhabesh Raj, Jonhnathan Ribeiro
Date: 2023-11-27
modified:2023-11-29
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
  • -'attack.s0349'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    TargetImage|endswith: '\lsass.exe'
    CallTrace|contains|all:
      -'_ctypes.pyd+'
      -':\Windows\System32\KERNELBASE.dll+'
      -':\Windows\SYSTEM32\ntdll.dll+'

    CallTrace|contains:
      -'python27.dll+'
      -'python3*.dll+'

    GrantedAccess: '0x1FFFFF'
  condition:selection
Falsepositives:
  -Unknown
Level: high