This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Lsass Full Dump Request Via DumpType Registry Settings
Original Source:
[Sigma source]
Title:
Lsass Full Dump Request Via DumpType Registry Settings
Status:
test
Description:
Detects the setting of the "DumpType" registry value to "2" which stands for a "Full Dump". Technique such as LSASS Shtinkering requires this value to be "2" in order to dump LSASS.
References:
-https://github.com/deepinstinct/Lsass-Shtinkering
-https://learn.microsoft.com/en-us/windows/win32/wer/collecting-user-mode-dumps
-https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf
Author:
@pbssubhash
Date:
2022-12-08
modified:
2023-08-17
Tags:
-'attack.credential-access'
-'attack.t1003.001'
Logsource:
category: registry_set
product: windows
Detection:
selection:
TargetObject|contains
:
-'\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\DumpType'
-'\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\lsass.exe\DumpType'
Details
:
'DWORD (0x00000002)'
condition
:
selection
Falsepositives:
-Legitimate application that needs to do a full dump of their process
Level:
high