HackTool - Pypykatz Credentials Dumping Activity

 Original Source: [Sigma source]
Title: HackTool - Pypykatz Credentials Dumping Activity
Status: test
Description:Detects the usage of "pypykatz" to obtain stored credentials. Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database through Windows registry where the SAM database is stored
References:
  -https://github.com/skelsec/pypykatz
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.002/T1003.002.md#atomic-test-2---registry-parse-with-pypykatz
Author: frack113
Date: 2022-01-05
modified:2023-02-05
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\pypykatz.exe'
      -'\python.exe'

    CommandLine|contains|all:
      -'live'
      -'registry'

  condition:selection
Falsepositives:
  -Unknown
Level: high