Windows Possible Credential Dumping

 Original Source: [splunk source]
Name:Windows Possible Credential Dumping
id:e4723b92-7266-11ec-af45-acde48001122
version:15
date:None
author:Michael Haag, Splunk
status:production
type:Anomaly
Description:The following analytic detects possible credential dumping by identifying suspicious process access to LSASS with credential-dumping-related call traces. It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_LIMITED_INFORMATION (0x1000) and PROCESS_DUP_HANDLE (0x40).
Data_source:
  • -Sysmon EventID 10
search:`sysmon`
EventCode=10
TargetImage=*\\lsass.exe
CallTrace IN (
"*dbgcore.dll*",
"*dbghelp.dll*",
"*kernel32.dll*",
"*kernelbase.dll*",
"*ntdll.dll*"
)
NOT SourceUser IN (
"NT AUTHORITY\\SYSTEM",
"NT AUTHORITY\\NETWORK SERVICE"
)

```
We looking for a value of PROCESS_QUERY_LIMITED_INFORMATION (0x1000) or PROCESS_DUP_HANDLE (0x40).
```
| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096
| eval PROCESS_DUP_HANDLE = 64
| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)
| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)
| where query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION
OR duplicate_handle_set == PROCESS_DUP_HANDLE

| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product

| eval CallTrace=split(CallTrace, "|")

| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_possible_credential_dumping_filter`


how_to_implement:To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Enabling EventCode 10 TargetProcess lsass.exe is required.
known_false_positives:False positives will occur when legitimate tools request query-limited or duplicate-handle access to LSASS. Filter based on source image as needed. Cobalt Strike usage of Mimikatz may generate this activity.
References:
  -https://en.wikipedia.org/wiki/Local_Security_Authority_Subsystem_Service
  -https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump
  -https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html
  -https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1
  -https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights?redirectedfrom=MSDN
  -https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/Windows/TestHarnesses/T1003.001_DumpLSASS/DumpLSASS.ps1
drilldown_searches:
 name:'View the detection results for - "$user_id$" and "$dest$"'
 search:'%original_detection_search% | search user_id = "$user_id$" dest = "$dest$"'
 earliest_offset:'$info_min_time$'
 latest_offset:'$info_max_time$'
 name:'View risk events for the last 7 days for - "$user_id$" and "$dest$"'
 search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user_id$", "$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
 earliest_offset:'7d'
 latest_offset:'0'
analytic_story:['Detect Zerologon Attack', 'CISA AA22-264A', 'Credential Dumping', 'CISA AA23-347A', 'DarkSide Ransomware', 'CISA AA22-257A', 'Scattered Lapsus$ Hunters']

asset_type:Endpoint

mitre_attack_id:['T1003.001']

product:['Splunk Enterprise', 'Splunk Enterprise Security', 'Splunk Cloud']

category:endpoint

security_domain:endpoint

tags:

tests:
 name:'True Positive Test'
 attack_data:
  data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon_creddump.log
  source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
  sourcetype: XmlWinEventLog
 test_type:'unit'
manual_test:None