DumpMinitool Execution

 Original Source: [Sigma source]
Title: DumpMinitool Execution
Status: test
Description:Detects the use of "DumpMinitool.exe" a tool that allows the dump of process memory via the use of the "MiniDumpWriteDump"
References:
  -https://twitter.com/mrd0x/status/1511415432888131586
  -https://twitter.com/mrd0x/status/1511489821247684615
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/
  -https://gist.github.com/nasbench/6d58c3c125e2fa1b8f7a09754c1b087f
Author: Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems)
Date: 2022-04-06
modified:2023-04-12
Tags:
  • -'attack.stealth'
  • -'attack.t1036'
  • -'attack.t1003.001'
  • -'attack.credential-access'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\DumpMinitool.exe'
      - '\DumpMinitool.x86.exe'
      - '\DumpMinitool.arm64.exe'
    - OriginalFileName:
      - 'DumpMinitool.exe'
      - 'DumpMinitool.x86.exe'
      - 'DumpMinitool.arm64.exe'
  selection_cli:
    CommandLine|contains:
      -' Full'
      -' Mini'
      -' WithHeap'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium