HackTool - CrackMapExec Process Patterns

 Original Source: [Sigma source]
Title: HackTool - CrackMapExec Process Patterns
Status: test
Description:Detects suspicious process patterns found in logs when CrackMapExec is used
References:
  -https://mpgn.gitbook.io/crackmapexec/smb-protocol/obtaining-credentials/dump-lsass
Author: Florian Roth (Nextron Systems)
Date: 2022-03-12
modified:2023-02-13
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_lsass_dump1:
    CommandLine|contains|all:
      -'tasklist /fi '
      -'Imagename eq lsass.exe'

    CommandLine|contains:
      -'cmd.exe /c '
      -'cmd.exe /r '
      -'cmd.exe /k '
      -'cmd /c '
      -'cmd /r '
      -'cmd /k '

    User|contains:
      -'AUTHORI'
      -'AUTORI'

  selection_lsass_dump2:
    CommandLine|contains|all:
      -'do rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump'
      -'\Windows\Temp\'
      -' full'
      -'%%B'

  selection_procdump:
    CommandLine|contains|all:
      -'tasklist /v /fo csv'
      -'findstr /i "lsass"'

  condition:1 of selection*
Falsepositives:
  -Unknown
Level: high