This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious LSASS Access Via MalSecLogon
Original Source:
[Sigma source]
Title:
Suspicious LSASS Access Via MalSecLogon
Status:
test
Description:
Detects suspicious access to LSASS handle via a call trace to "seclogon.dll" with a suspicious access right.
References:
-https://twitter.com/SBousseaden/status/1541920424635912196
-https://github.com/elastic/detection-rules/blob/2bc1795f3d7bcc3946452eb4f07ae799a756d94e/rules/windows/credential_access_lsass_handle_via_malseclogon.toml
-https://splintercod3.blogspot.com/p/the-hidden-side-of-seclogon-part-3.html
Author:
Samir Bousseaden (original elastic rule), Nasreddine Bencherchali (Nextron Systems)
Date:
2022-06-29
modified:
None
Tags:
-'attack.credential-access'
-'attack.t1003.001'
Logsource:
category: process_access
product: windows
Detection:
selection:
TargetImage|endswith
:
'\lsass.exe'
SourceImage|endswith
:
'\svchost.exe'
GrantedAccess
:
'0x14c0'
CallTrace|contains
:
'seclogon.dll'
condition
:
selection
Falsepositives:
-Unknown
Level:
high