Suspicious LSASS Access Via MalSecLogon

 Original Source: [Sigma source]
Title: Suspicious LSASS Access Via MalSecLogon
Status: test
Description:Detects suspicious access to LSASS handle via a call trace to "seclogon.dll" with a suspicious access right.
References:
  -https://twitter.com/SBousseaden/status/1541920424635912196
  -https://github.com/elastic/detection-rules/blob/2bc1795f3d7bcc3946452eb4f07ae799a756d94e/rules/windows/credential_access_lsass_handle_via_malseclogon.toml
  -https://splintercod3.blogspot.com/p/the-hidden-side-of-seclogon-part-3.html
Author: Samir Bousseaden (original elastic rule), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-29
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    TargetImage|endswith: '\lsass.exe'
    SourceImage|endswith: '\svchost.exe'
    GrantedAccess: '0x14c0'
    CallTrace|contains: 'seclogon.dll'
  condition:selection
Falsepositives:
  -Unknown
Level: high