Potential SysInternals ProcDump Evasion

 Original Source: [Sigma source]
Title: Potential SysInternals ProcDump Evasion
Status: test
Description:Detects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name
References:
  -https://twitter.com/mrd0x/status/1480785527901204481
Author: Florian Roth (Nextron Systems)
Date: 2022-01-11
modified:2023-05-09
Tags:
  • -'attack.stealth'
  • -'attack.t1036'
  • -'attack.t1003.001'
  • -'attack.credential-access'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_1:
    CommandLine|contains:
      -'copy procdump'
      -'move procdump'

  selection_2:
    CommandLine|contains|all:
      -'copy '
      -'.dmp '

    CommandLine|contains:
      -'2.dmp'
      -'lsass'
      -'out.dmp'

  selection_3:
    CommandLine|contains:
      -'copy lsass.exe_'
      -'move lsass.exe_'

  condition:1 of selection_*
Falsepositives:
  -False positives are expected in cases in which ProcDump just gets copied to a different directory without any renaming
Level: high