Potential Credential Dumping Via WER

 Original Source: [Sigma source]
Title: Potential Credential Dumping Via WER
Status: test
Description:Detects potential credential dumping via Windows Error Reporting LSASS Shtinkering technique which uses the Windows Error Reporting to dump lsass
References:
  -https://github.com/deepinstinct/Lsass-Shtinkering
  -https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf
Author: @pbssubhash , Nasreddine Bencherchali
Date: 2022-12-08
modified:2022-12-09
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\Werfault.exe' OriginalFileName:'WerFault.exe'   selection_cli:
    ParentUser|contains:
      -'AUTHORI'
      -'AUTORI'

    User|contains:
      -'AUTHORI'
      -'AUTORI'

    CommandLine|contains|all:
      -' -u -p '
      -' -ip '
      -' -s '

  filter_lsass:
    ParentImage: 'C:\Windows\System32\lsass.exe'
  condition:all of selection_* and not 1 of filter_*
Falsepositives:
  -Windows Error Reporting might produce similar behavior. In that case, check the PID associated with the "-p" parameter in the CommandLine.
Level: high