HackTool - HandleKatz LSASS Dumper Execution

 Original Source: [Sigma source]
Title: HackTool - HandleKatz LSASS Dumper Execution
Status: test
Description:Detects the use of HandleKatz, a tool that demonstrates the usage of cloned handles to Lsass in order to create an obfuscated memory dump of the same
References:
  -https://github.com/codewhitesec/HandleKatz
Author: Florian Roth (Nextron Systems)
Date: 2022-08-18
modified:2024-11-23
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_loader_img:
    Image|endswith: '\loader.exe'
    CommandLine|contains: '--pid:'
  selection_loader_imphash:
    Hashes|contains:
      -'IMPHASH=38D9E015591BBFD4929E0D0F47FA0055'
      -'IMPHASH=0E2216679CA6E1094D63322E3412D650'

  selection_flags:
    CommandLine|contains|all:
      -'--pid:'
      -'--outfile:'

    CommandLine|contains:
      -'.dmp'
      -'lsass'
      -'.obf'
      -'dump'

  condition:1 of selection_*
Falsepositives:
  -Unknown
Level: high