Password Dumper Activity on LSASS

 Original Source: [Sigma source]
Title: Password Dumper Activity on LSASS
Status: test
Description:Detects process handle on LSASS process with certain access mask and object type SAM_DOMAIN
References:
  -https://twitter.com/jackcr/status/807385668833968128
Author: sigma
Date: 2017-02-12
modified:2022-10-09
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '4656'
    ProcessName|endswith: '\lsass.exe'
    AccessMask: '0x705'
    ObjectType: 'SAM_DOMAIN'
  condition:selection
Falsepositives:
  -Unknown
Level: high