HackTool - Dumpert Process Dumper Execution

 Original Source: [Sigma source]
Title: HackTool - Dumpert Process Dumper Execution
Status: test
Description:Detects the use of Dumpert process dumper, which dumps the lsass.exe process memory
References:
  -https://github.com/outflanknl/Dumpert
  -https://unit42.paloaltonetworks.com/actors-still-exploiting-sharepoint-vulnerability/
Author: Florian Roth (Nextron Systems)
Date: 2020-02-04
modified:2026-09-16
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Hashes|contains:'IMPHASH=09D278F9DE118EF09163C6140255C690'     - CommandLine|contains:
      - 'Dumpert.dll'
      - 'Dumpert.exe'
  condition:selection
Falsepositives:
  -Very unlikely
Level: critical