Lsass Full Dump Request Via DumpType Registry Settings

 Original Source: [Sigma source]
Title: Lsass Full Dump Request Via DumpType Registry Settings
Status: test
Description:Detects the setting of the "DumpType" registry value to "2" which stands for a "Full Dump". Technique such as LSASS Shtinkering requires this value to be "2" in order to dump LSASS.
References:
  -https://github.com/deepinstinct/Lsass-Shtinkering
  -https://learn.microsoft.com/en-us/windows/win32/wer/collecting-user-mode-dumps
  -https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf
Author: @pbssubhash
Date: 2022-12-08
modified:2023-08-17
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains:
      -'\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\DumpType'
      -'\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps\lsass.exe\DumpType'

    Details: 'DWORD (0x00000002)'
  condition:selection
Falsepositives:
  -Legitimate application that needs to do a full dump of their process
Level: high