{"id":"T1003.001","name":"LSASS Memory","url":"https://attack.mitre.org/techniques/T1003/001","tactics":["credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0363","stix_id":"x-mitre-detection-strategy--793c70fb-bc7a-4a77-95aa-7b0c583f10b4","name":"Detection of Credential Dumping from LSASS Memory via Access and Dump Sequence","url":"https://attack.mitre.org/detectionstrategies/DET0363","analytics":[{"id":"AN1030","stix_id":"x-mitre-analytic--2b0dd3b6-6949-4dd5-b0dd-7b0b6f431dbe","name":"Analytic 1030","description":"A non-privileged or abnormal process attempts to open a handle with full access (0x1F0FFF) to lsass.exe and subsequently invokes memory dump, file creation, or registry modification indicative of credential scraping. This behavior chain reflects staged credential theft activity.","url":"https://attack.mitre.org/detectionstrategies/DET0363#AN1030","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4673","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AccessMask","description":"Set to 0x1F0FFF to detect full memory access attempts; can be scoped down to reduce noise."},{"field":"TimeWindow","description":"Defines time between LSASS access and dump file creation or registry modification (e.g., 5 minutes)."},{"field":"ParentProcessName","description":"Allowlist known legitimate tools (e.g., AV/EDR) accessing lsass.exe."},{"field":"DumpFilePath","description":"Paths where memory dumps are written, e.g., %TEMP%, C:\\Windows\\Temp."},{"field":"CommandLinePattern","description":"Common dumping syntax like rundll32, procdump, comsvcs.dll, Invoke-Mimikatz."}],"live":true,"detection_strategies":["DET0363"],"techniques":["T1003.001"]}],"live":true,"version":"1.0","techniques":["T1003.001"]}],"sigma_rules":[{"id":"03e2746e-2b31-42f1-ab7a-eb39365b2422","title":"APT31 Judgement Panda Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2019-02-21","modified":"2023-03-10","description":"Detects APT31 Judgement Panda activity as described in the Crowdstrike 2019 Global Threat Report","references":["https://www.documentcloud.org/documents/5743766-Global-Threat-Report-2019.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.collection","attack.lateral-movement","attack.credential-access","attack.g0128","attack.t1003.001","attack.t1560.001","detection.emerging-threats"],"path":"rules-emerging-threats/2019/TA/APT31/proc_creation_win_apt_apt31_judgement_panda.yml","techniques":["T1003.001","T1560.001"],"cves":[]},{"id":"03f4ca17-de95-428d-a75a-4ee78b047256","title":"HackTool - Impacket File Indicators","author":"The DFIR Report, IrishDeath","status":"experimental","level":"high","date":"2025-05-19","modified":null,"description":"Detects file creation events with filename patterns used by Impacket.","references":["https://thedfirreport.com/2025/05/19/another-confluence-bites-the-dust-falling-to-elpaco-team-ransomware/","https://github.com/fortra/impacket"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/file/file_event/file_event_win_impacket_file_indicators.yml","techniques":["T1003.001"],"cves":[]},{"id":"06d71506-7beb-4f22-8888-e2e5e2ca7fd8","title":"Mimikatz Use","author":"Florian Roth (Nextron Systems), David ANDRE (additional keywords)","status":"test","level":"high","date":"2017-01-10","modified":"2022-01-05","description":"This method detects mimikatz keywords in different Eventlogs (some of them only appear in older Mimikatz version that are however still used by different threat groups)","references":["https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows"},"tags":["attack.s0002","attack.lateral-movement","attack.credential-access","car.2013-07-001","car.2019-04-004","attack.t1003.002","attack.t1003.004","attack.t1003.001","attack.t1003.006"],"path":"rules/windows/builtin/win_alert_mimikatz_keywords.yml","techniques":["T1003.002","T1003.004","T1003.001","T1003.006"],"cves":[]},{"id":"0b4ae027-2a2d-4b93-8c7e-962caaba5b2a","title":"Time Travel Debugging Utility Usage","author":"Ensar Şamil, @sblmsrsn, @oscd_initiative","status":"test","level":"high","date":"2020-10-06","modified":"2022-10-09","description":"Detects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.","references":["https://lolbas-project.github.io/lolbas/Binaries/Tttracer/","https://twitter.com/mattifestation/status/1196390321783025666","https://twitter.com/oulusoyum/status/1191329746069655553"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.stealth","attack.t1218","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml","techniques":["T1218","T1003.001"],"cves":[]},{"id":"0e277796-5f23-4e49-a490-483131d4f6e1","title":"Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process","author":"Perez Diego (@darkquassar), oscd.community, Ecco","status":"test","level":"medium","date":"2019-10-27","modified":"2024-03-01","description":"Detects the load of dbghelp/dbgcore DLL by a potentially uncommon or potentially suspicious process.\nThe Dbghelp and Dbgcore DLLs export functions that allow for the dump of process memory. Tools like ProcessHacker, Task Manager and some attacker tradecraft use the MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll.\nAs an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine.\nKeep in mind that many legitimate Windows processes and services might load the aforementioned DLLs for debugging or other related purposes. Investigate the CommandLine and the Image location of the process loading the DLL.\n","references":["https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump","https://www.pinvoke.net/default.aspx/dbghelp/MiniDumpWriteDump.html","https://medium.com/@fsx30/bypass-edrs-memory-protection-introduction-to-hooking-2efb21acffd6"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.credential-access","attack.t1003.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/image_load/image_load_dll_dbghelp_dbgcore_susp_load.yml","techniques":["T1003.001"],"cves":[]},{"id":"0f920ebe-7aea-4c54-b202-9aa0c609cfe5","title":"Potential Credential Dumping Attempt Via PowerShell","author":"oscd.community, Natalia Shornikova","status":"test","level":"medium","date":"2020-10-06","modified":"2023-11-28","description":"Detects a PowerShell process requesting access to \"lsass.exe\", which can be indicative of potential credential dumping attempts","references":["https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_access/proc_access_win_lsass_powershell_access.yml","techniques":["T1003.001"],"cves":[]},{"id":"129966c9-de17-4334-a123-8b58172e664d","title":"Potential Windows Defender AV Bypass Via Dump64.EXE Rename","author":"Austin Songer @austinsonger, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-11-26","modified":"2024-06-21","description":"Detects when a user is potentially trying to bypass the Windows Defender AV by renaming a tool to dump64.exe and placing it in the Visual Studio folder.\nCurrently the rule is covering only usage of procdump but other utilities can be added in order to increase coverage.\n","references":["https://twitter.com/mrd0x/status/1460597833917251595"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_dump64_defender_av_bypass_rename.yml","techniques":["T1003.001"],"cves":[]},{"id":"1a1ed54a-2ba4-4221-94d5-01dee560d71e","title":"Renamed CreateDump Utility Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-09-20","modified":"2023-02-14","description":"Detects uses of a renamed legitimate createdump.exe LOLOBIN utility to dump process memory","references":["https://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/","https://twitter.com/bopin2020/status/1366400799199272960"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036","attack.t1003.001","attack.credential-access"],"path":"rules/windows/process_creation/proc_creation_win_renamed_createdump.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"1f0b4cac-9c81-41f4-95d0-8475ff46b3e2","title":"PPL Tampering Via WerFaultSecure","author":"Jason (https://github.com/0xbcf)","status":"experimental","level":"high","date":"2025-09-23","modified":"2025-11-23","description":"Detects potential abuse of WerFaultSecure.exe to dump Protected Process Light (PPL) processes like LSASS or to freeze security solutions (EDR/antivirus).\nThis technique is used by tools such as EDR-Freeze and WSASS to bypass PPL protections and access sensitive information or disable security software.\nDistinct command line patterns help identify the specific tool:\n- WSASS usage typically shows: \"WSASS.exe WerFaultSecure.exe [PID]\" in ParentCommandLine\n- EDR-Freeze usage typically shows: \"EDR-Freeze_[version].exe [PID] [timeout]\" in ParentCommandLine\nLegitimate debugging operations using WerFaultSecure are rare in production environments and should be investigated.\n","references":["https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html","https://github.com/TwoSevenOneT/EDR-Freeze/blob/a7f61030b36fbde89871f393488f7075d2aa89f6/EDR-Freeze.cpp#L53","https://www.zerosalarium.com/2025/09/Dumping-LSASS-With-WER-On-Modern-Windows-11.html","https://github.com/TwoSevenOneT/WSASS/blob/2c8fd9fa32143e7bc9f066e9511c6f8a57bc64b5/WSASS.cpp#L251"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1685","attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_werfaultsecure_abuse.yml","techniques":["T1685","T1003.001"],"cves":[]},{"id":"23ceaf5c-b6f1-4a32-8559-f2ff734be516","title":"Dumping Process via Sqldumper.exe","author":"Kirill Kiryanov, oscd.community","status":"test","level":"medium","date":"2020-10-08","modified":"2021-11-27","description":"Detects process dump via legitimate sqldumper.exe binary","references":["https://twitter.com/countuponsec/status/910977826853068800","https://twitter.com/countuponsec/status/910969424215232518","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Sqldumper/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml","techniques":["T1003.001"],"cves":[]},{"id":"2704ab9e-afe2-4854-a3b1-0c0706d03578","title":"HackTool - Dumpert Process Dumper Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-02-04","modified":"2025-01-22","description":"Detects the use of Dumpert process dumper, which dumps the lsass.exe process memory","references":["https://github.com/outflanknl/Dumpert","https://unit42.paloaltonetworks.com/actors-still-exploiting-sharepoint-vulnerability/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_dumpert.yml","techniques":["T1003.001"],"cves":[]},{"id":"2e65275c-8288-4ab4-aeb7-6274f58b6b20","title":"Procdump Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2021-08-16","modified":"2026-06-29","description":"Detects usage of the SysInternals Procdump utility","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036","attack.t1003.001","attack.credential-access"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_procdump.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"2e69f167-47b5-4ae7-a390-47764529eff5","title":"Transferring Files with Credential Data via Network Shares - Zeek","author":"@neu5ron, Teymur Kheirkhabarov, oscd.community","status":"test","level":"medium","date":"2020-04-02","modified":"2021-11-27","description":"Transferring files with well-known filenames (sensitive files with credential data) using network shares","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"zeek","service":"smb_files"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.001","attack.t1003.003"],"path":"rules/network/zeek/zeek_smb_converted_win_transferring_files_with_credential_data.yml","techniques":["T1003.002","T1003.001","T1003.003"],"cves":[]},{"id":"2f869d59-7f6a-4931-992c-cce556ff2d53","title":"Potential Adplus.EXE Abuse","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-09","modified":"2023-06-23","description":"Detects execution of \"AdPlus.exe\", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.","references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Adplus/","https://twitter.com/nas_bench/status/1534916659676422152","https://twitter.com/nas_bench/status/1534915321856917506"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_adplus_memory_dump.yml","techniques":["T1003.001"],"cves":[]},{"id":"33efc23c-6ea2-4503-8cfe-bdf82ce8f719","title":"Lsass Full Dump Request Via DumpType Registry Settings","author":"@pbssubhash","status":"test","level":"high","date":"2022-12-08","modified":"2023-08-17","description":"Detects the setting of the \"DumpType\" registry value to \"2\" which stands for a \"Full Dump\". Technique such as LSASS Shtinkering requires this value to be \"2\" in order to dump LSASS.","references":["https://github.com/deepinstinct/Lsass-Shtinkering","https://learn.microsoft.com/en-us/windows/win32/wer/collecting-user-mode-dumps","https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/registry/registry_set/registry_set_lsass_usermode_dumping.yml","techniques":["T1003.001"],"cves":[]},{"id":"36d88494-1d43-4dc0-b3fa-35c8fea0ca9d","title":"HackTool - CreateMiniDump Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-12-22","modified":"2024-11-23","description":"Detects the use of CreateMiniDump hack tool used to dump the LSASS process memory for credential extraction on the attacker's machine","references":["https://ired.team/offensive-security/credential-access-and-credential-dumping/dumping-lsass-passwords-without-mimikatz-minidumpwritedump-av-signature-bypass"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_createminidump.yml","techniques":["T1003.001"],"cves":[]},{"id":"472159c5-31b9-4f56-b794-b766faa8b0a7","title":"Suspicious LSASS Access Via MalSecLogon","author":"Samir Bousseaden (original elastic rule), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-29","modified":null,"description":"Detects suspicious access to LSASS handle via a call trace to \"seclogon.dll\" with a suspicious access right.","references":["https://twitter.com/SBousseaden/status/1541920424635912196","https://github.com/elastic/detection-rules/blob/2bc1795f3d7bcc3946452eb4f07ae799a756d94e/rules/windows/credential_access_lsass_handle_via_malseclogon.toml","https://splintercod3.blogspot.com/p/the-hidden-side-of-seclogon-part-3.html"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_access/proc_access_win_lsass_seclogon_access.yml","techniques":["T1003.001"],"cves":[]},{"id":"4976aa50-8f41-45c6-8b15-ab3fc10e79ed","title":"Credential Dumping Tools Service Execution - System","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/system/service_control_manager/win_system_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"4a1b6da0-d94f-4fc3-98fc-2d9cb9e5ee76","title":"Potentially Suspicious AccessMask Requested From LSASS","author":"Roberto Rodriguez, Teymur Kheirkhabarov, Dimitrios Slamaris, Mark Russinovich, Aleksey Potapov, oscd.community (update)","status":"test","level":"medium","date":"2019-11-01","modified":"2026-06-29","description":"Detects process handle on LSASS process with certain access mask","references":["https://web.archive.org/web/20230208123920/https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html","https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","car.2019-04-004","attack.t1003.001"],"path":"rules/windows/builtin/security/win_security_susp_lsass_dump_generic.yml","techniques":["T1003.001"],"cves":[]},{"id":"4be8b654-0c01-4c9d-a10c-6b28467fc651","title":"LSASS Access From Potentially White-Listed Processes","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-10","modified":"2023-11-29","description":"Detects a possible process memory dump that uses a white-listed filename like TrolleyExpress.exe as a way to dump the LSASS process memory without Microsoft Defender interference\n","references":["https://twitter.com/_xpn_/status/1491557187168178176","https://www.ired.team/offensive-security/credential-access-and-credential-dumping/dump-credentials-from-lsass-process-without-mimikatz","https://twitter.com/mrd0x/status/1460597833917251595"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0002"],"path":"rules/windows/process_access/proc_access_win_lsass_whitelisted_process_names.yml","techniques":["T1003.001"],"cves":[]},{"id":"4c0aaedc-154c-4427-ada0-d80ef9c9deb6","title":"Process Access via TrolleyExpress Exclusion","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-10","modified":"2022-05-13","description":"Detects a possible process memory dump that uses the white-listed Citrix TrolleyExpress.exe filename as a way to dump the lsass process memory","references":["https://twitter.com/_xpn_/status/1491557187168178176","https://www.youtube.com/watch?v=Ie831jF0bb0"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.011","attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_citrix_trolleyexpress_procdump.yml","techniques":["T1218.011","T1003.001"],"cves":[]},{"id":"515c8be5-e5df-4c5e-8f6d-a4a2f05e4b48","title":"CreateDump Process Dump","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-01-04","modified":"2022-08-19","description":"Detects uses of the createdump.exe LOLOBIN utility to dump process memory","references":["https://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/","https://twitter.com/bopin2020/status/1366400799199272960"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036","attack.t1003.001","attack.credential-access"],"path":"rules/windows/process_creation/proc_creation_win_createdump_lolbin_execution.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"55e29995-75e7-451a-bef0-6225e2f13597","title":"Potential Credential Dumping Via LSASS SilentProcessExit Technique","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-02-26","modified":"2022-12-19","description":"Detects changes to the Registry in which a monitor program gets registered to dump the memory of the lsass.exe process","references":["https://www.deepinstinct.com/2021/02/16/lsass-memory-dumps-are-stealthier-than-ever-before-part-2/","https://oddvar.moe/2018/04/10/persistence-using-globalflags-in-image-file-execution-options-hidden-from-autoruns-exe/"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/registry/registry_event/registry_event_silentprocessexit_lsass.yml","techniques":["T1003.001"],"cves":[]},{"id":"589ac73f-8e12-409c-964e-31a2f5775ae2","title":"HackTool - WSASS Execution","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-23","modified":"2026-01-09","description":"Detects execution of WSASS, a tool used to dump LSASS memory on Windows systems by leveraging WER's\n(Windows Error Reporting) WerFaultSecure.EXE to bypass PPL (Protected Process Light) protections.\n","references":["https://github.com/TwoSevenOneT/WSASS","https://www.zerosalarium.com/2025/09/Dumping-LSASS-With-WER-On-Modern-Windows-11.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_wsass.yml","techniques":["T1003.001"],"cves":[]},{"id":"5afee48e-67dd-4e03-a783-f74259dcf998","title":"Potential LSASS Process Dump Via Procdump","author":"Florian Roth (Nextron Systems)","status":"stable","level":"high","date":"2018-10-30","modified":"2025-10-19","description":"Detects potential credential harvesting attempts through LSASS memory dumps using ProcDump.\nThis rule identifies suspicious command-line patterns that combine memory dump flags (-ma, -mm, -mp) with LSASS-related process markers.\nLSASS (Local Security Authority Subsystem Service) contains sensitive authentication data including plaintext passwords, NTLM hashes, and Kerberos tickets in memory.\nAttackers commonly dump LSASS memory to extract credentials for lateral movement and privilege escalation.\n","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/procdump","https://research.splunk.com/endpoint/3742ebfe-64c2-11eb-ae93-0242ac130002","https://x.com/wietze/status/1958302556033065292?s=12"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036","attack.credential-access","attack.t1003.001","car.2013-05-009"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_procdump_lsass.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"5ef9853e-4d0e-4a70-846f-a9ca37d876da","title":"Potential Credential Dumping Activity Via LSASS","author":"Samir Bousseaden, Michael Haag","status":"test","level":"medium","date":"2019-04-03","modified":"2026-06-29","description":"Detects process access requests to the LSASS process with specific call trace calls and access masks.\nThis behaviour is expressed by many credential dumping tools such as Mimikatz, NanoDump, Invoke-Mimikatz, Procdump and even the Taskmgr dumping feature.\n","references":["https://web.archive.org/web/20230329170326/https://blog.menasec.net/2019/02/threat-hunting-21-procdump-or-taskmgr.html","https://web.archive.org/web/20230208123920/https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1003.001/T1003.001.md","https://research.splunk.com/endpoint/windows_possible_credential_dumping/"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0002"],"path":"rules/windows/process_access/proc_access_win_lsass_memdump.yml","techniques":["T1003.001"],"cves":[]},{"id":"646ea171-dded-4578-8a4d-65e9822892e3","title":"Process Memory Dump Via Comsvcs.DLL","author":"Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)","status":"test","level":"high","date":"2020-02-18","modified":"2025-02-23","description":"Detects a process memory dump via \"comsvcs.dll\" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)","references":["https://twitter.com/shantanukhande/status/1229348874298388484","https://twitter.com/pythonresponder/status/1385064506049630211?s=21","https://twitter.com/Hexacorn/status/1224848930795552769","https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/","https://twitter.com/SBousseaden/status/1167417096374050817","https://twitter.com/Wietze/status/1542107456507203586","https://github.com/Hackndo/lsassy/blob/14d8f8ae596ecf22b449bfe919829173b8a07635/lsassy/dumpmethod/comsvcs.py","https://www.youtube.com/watch?v=52tAmVLg1KM&t=2070s"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.stealth","attack.t1036","attack.t1003.001","car.2013-05-009"],"path":"rules/windows/process_creation/proc_creation_win_rundll32_process_dump_via_comsvcs.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"66e563f9-1cbd-4a22-a957-d8b7c0f44372","title":"HackTool - XORDump Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-01-28","modified":"2023-02-08","description":"Detects suspicious use of XORDump process memory dumping utility","references":["https://github.com/audibleblink/xordump"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036","attack.t1003.001","attack.credential-access"],"path":"rules/windows/process_creation/proc_creation_win_hktl_xordump.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"678dfc63-fefb-47a5-a04c-26bcf8cc9f65","title":"Uncommon GrantedAccess Flags On LSASS","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-03-13","modified":"2023-11-30","description":"Detects process access to LSASS memory with uncommon access flags 0x410 and 0x01410","references":["https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights","https://onedrive.live.com/view.aspx?resid=D026B4699190F1E6!2843&ithint=file%2cpptx&app=PowerPoint&authkey=!AMvCRTKB_V1J5ow","https://web.archive.org/web/20230208123920/https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html","https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://web.archive.org/web/20230420013146/http://security-research.dyndns.org/pub/slides/FIRST2017/FIRST-2017_Tom-Ueltschi_Sysmon_FINAL_notes.pdf"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0002","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_access/proc_access_win_lsass_uncommon_access_flag.yml","techniques":["T1003.001"],"cves":[]},{"id":"6902955a-01b7-432c-b32a-6f5f81d8f625","title":"LSASS Process Dump Artefact In CrashDumps Folder","author":"@pbssubhash","status":"test","level":"high","date":"2022-12-08","modified":null,"description":"Detects the presence of an LSASS dump file in the \"CrashDumps\" folder. This could be a sign of LSASS credential dumping. Techniques such as the LSASS Shtinkering have been seen abusing the Windows Error Reporting to dump said process.","references":["https://github.com/deepinstinct/Lsass-Shtinkering","https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/file/file_event/file_event_win_lsass_shtinkering.yml","techniques":["T1003.001"],"cves":[]},{"id":"69ca12af-119d-44ed-b50f-a47af0ebc364","title":"LSASS Process Memory Dump Creation Via Taskmgr.EXE","author":"Swachchhanda Shrawan Poudel","status":"test","level":"high","date":"2023-10-19","modified":null,"description":"Detects the creation of an \"lsass.dmp\" file by the taskmgr process. This indicates a manual dumping of the LSASS.exe process memory using Windows Task Manager.","references":["https://github.com/redcanaryco/atomic-red-team/blob/987e3ca988ae3cff4b9f6e388c139c05bf44bbb8/atomics/T1003.001/T1003.001.md#L1"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/file/file_event/file_event_win_taskmgr_lsass_dump.yml","techniques":["T1003.001"],"cves":[]},{"id":"736ffa74-5f6f-44ca-94ef-1c0df4f51d2a","title":"HackTool - CrackMapExec File Indicators","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2024-03-11","modified":"2024-06-27","description":"Detects file creation events with filename patterns used by CrackMapExec.","references":["https://github.com/byt3bl33d3r/CrackMapExec/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/file/file_event/file_event_win_hktl_crackmapexec_indicators.yml","techniques":["T1003.001"],"cves":[]},{"id":"78cc2dd2-7d20-4d32-93ff-057084c38b93","title":"Antivirus - Password Dumper Signature","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"stable","level":"critical","date":"2018-09-09","modified":"2026-06-15","description":"Detects a highly relevant Antivirus alert that reports password dumpers and stealers.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place and check if passwords need to be reset.\n","references":["https://www.nextron-systems.com/?s=antivirus","https://www.virustotal.com/gui/file/5fcda49ee7f202559a6cbbb34edb65c33c9a1e0bde9fa2af06a6f11b55ded619","https://www.virustotal.com/gui/file/a4edfbd42595d5bddb442c82a02cf0aaa10893c1bf79ea08b9ce576f82749448"],"logsource":{"category":"antivirus"},"tags":["attack.credential-access","attack.t1003","attack.t1558","attack.t1003.001","attack.t1003.002"],"path":"rules/category/antivirus/av_password_dumper.yml","techniques":["T1003","T1558","T1003.001","T1003.002"],"cves":[]},{"id":"79aeeb41-8156-4fac-a0cd-076495ab82a1","title":"NotPetya Ransomware Activity","author":"Florian Roth (Nextron Systems), Tom Ueltschi","status":"test","level":"critical","date":"2019-01-16","modified":"2022-12-15","description":"Detects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil","references":["https://securelist.com/schroedingers-petya/78870/","https://www.hybrid-analysis.com/sample/64b0b58a2c030c77fdb2b537b2fcc4af432bc55ffb36599a31d418c7c69e94b1?environmentId=100"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.defense-impairment","attack.t1218.011","attack.t1685.005","attack.credential-access","attack.t1003.001","car.2016-04-002","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Malware/NotPetya/proc_creation_win_malware_notpetya.yml","techniques":["T1218.011","T1685.005","T1003.001"],"cves":[]},{"id":"79b06761-465f-4f88-9ef2-150e24d3d737","title":"Potential SysInternals ProcDump Evasion","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-01-11","modified":"2023-05-09","description":"Detects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name","references":["https://twitter.com/mrd0x/status/1480785527901204481"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036","attack.t1003.001","attack.credential-access"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_procdump_evasion.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"7aa7009a-28b9-4344-8c1f-159489a390df","title":"HackTool - Windows Credential Editor (WCE) Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2019-12-31","modified":"2025-10-21","description":"Detects the use of Windows Credential Editor (WCE), a popular post-exploitation tool used to extract plaintext passwords, hash, PIN code and Kerberos tickets from memory.\nIt is often used by threat actors for credential dumping and lateral movement within compromised networks.\n","references":["https://www.ampliasecurity.com/research/windows-credentials-editor/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001","attack.s0005"],"path":"rules/windows/process_creation/proc_creation_win_hktl_wce.yml","techniques":["T1003.001"],"cves":[]},{"id":"84c174ab-d3ef-481f-9c86-a50d0b8e3edb","title":"PowerShell Get-Process LSASS in ScriptBlock","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-04-23","modified":"2022-12-25","description":"Detects a Get-Process command on lsass process, which is in almost all cases a sign of malicious activity","references":["https://web.archive.org/web/20220205033028/https://twitter.com/PythonResponder/status/1385064506049630211"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_getprocess_lsass.yml","techniques":["T1003.001"],"cves":[]},{"id":"857c8db3-c89b-42fb-882b-f681c7cf4da2","title":"Unsigned Image Loaded Into LSASS Process","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"medium","date":"2019-10-22","modified":"2021-11-27","description":"Loading unsigned image (DLL, EXE) into LSASS process","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/image_load/image_load_lsass_unsigned_image_load.yml","techniques":["T1003.001"],"cves":[]},{"id":"8a1b2c3d-4e5f-6789-abcd-ef1234567890","title":"PUA - Memory Dump Mount Via MemProcFS","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-27","modified":null,"description":"Detects execution of MemProcFS a memory forensics tool with the '-device' parameter.\nMemProcFS mounts physical memory as a virtual file system, allowing direct access to process memory and system structures.\nThreat actors were seen abusing this utility to mount memory dumps and then extract sensitive information from processes like LSASS or extract registry hives to obtain credentials, LSA secrets, SAM data, and cached domain credentials.\nMemProcFS usage that is not part of authorized forensic analysis should be treated as suspicious and warrants further investigation.\n","references":["https://github.com/ufrisk/MemProcFS","https://0xdf.gitlab.io/2024/10/05/htb-freelancer.html#","https://www.huntress.com/blog/curling-for-data-a-dive-into-a-threat-actors-malicious-ttps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003","attack.t1003.001","attack.t1003.004","attack.t1003.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_memprocfs.yml","techniques":["T1003","T1003.001","T1003.004","T1003.002"],"cves":[]},{"id":"8cde342c-ba48-4b74-b615-172c330f2e93","title":"Suspicious Renamed Comsvcs DLL Loaded By Rundll32","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-14","modified":"2023-02-17","description":"Detects rundll32 loading a renamed comsvcs.dll to dump process memory","references":["https://twitter.com/sbousseaden/status/1555200155351228419"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/image_load/image_load_dll_comsvcs_load_renamed_version_by_rundll32.yml","techniques":["T1003.001"],"cves":[]},{"id":"8fbf3271-1ef6-4e94-8210-03c2317947f6","title":"Cred Dump Tools Dropped Files","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"high","date":"2019-11-01","modified":"2025-10-25","description":"Files with well-known filenames (parts of credential dump software or files produced by them) creation","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.003","attack.t1003.004","attack.t1003.005"],"path":"rules/windows/file/file_event/file_event_win_cred_dump_tools_dropped_files.yml","techniques":["T1003.001","T1003.002","T1003.003","T1003.004","T1003.005"],"cves":[]},{"id":"910ab938-668b-401b-b08c-b596e80fdca5","title":"Transferring Files with Credential Data via Network Shares","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"medium","date":"2019-10-22","modified":"2025-07-11","description":"Transferring files with well-known filenames (sensitive files with credential data) using network shares","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.002","attack.t1003.001","attack.t1003.003"],"path":"rules/windows/builtin/security/win_security_transf_files_with_cred_data_via_network_shares.yml","techniques":["T1003.002","T1003.001","T1003.003"],"cves":[]},{"id":"93d94efc-d7ad-4161-ad7d-1638c4f908d8","title":"HackTool - Dumpert Process Dumper Default File","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-02-04","modified":"2023-05-09","description":"Detects the creation of the default dump file used by Outflank Dumpert tool. A process dumper, which dumps the lsass process memory","references":["https://github.com/outflanknl/Dumpert","https://unit42.paloaltonetworks.com/actors-still-exploiting-sharepoint-vulnerability/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/file/file_event/file_event_win_hktl_dumpert.yml","techniques":["T1003.001"],"cves":[]},{"id":"961d0ba2-3eea-4303-a930-2cf78bbfcc5e","title":"HackTool - Credential Dumping Tools Named Pipe Created","author":"Teymur Kheirkhabarov, oscd.community","status":"test","level":"critical","date":"2019-11-01","modified":"2023-08-07","description":"Detects well-known credential dumping tools execution via specific named pipe creation","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://image.slidesharecdn.com/zeronights2017kheirkhabarov-171118103000/75/hunting-for-credentials-dumping-in-windows-environment-57-2048.jpg?cb=1666035799"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005"],"path":"rules/windows/pipe_created/pipe_created_hktl_generic_cred_dump_tools_pipes.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005"],"cves":[]},{"id":"962fe167-e48d-4fd6-9974-11e5b9a5d6d1","title":"LSASS Access From Non System Account","author":"Roberto Rodriguez @Cyb3rWard0g","status":"test","level":"medium","date":"2019-06-20","modified":"2023-12-11","description":"Detects potential mimikatz-like tools accessing LSASS from non system account","references":["https://threathunterplaybook.com/hunts/windows/170105-LSASSMemoryReadAccess/notebook.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/builtin/security/win_security_lsass_access_non_system_account.yml","techniques":["T1003.001"],"cves":[]},{"id":"9a4ccd1a-3526-4d99-b980-9f9c5d3a6ff3","title":"Potential Credential Dumping Via WER","author":"@pbssubhash , Nasreddine Bencherchali","status":"test","level":"high","date":"2022-12-08","modified":"2022-12-09","description":"Detects potential credential dumping via Windows Error Reporting LSASS Shtinkering technique which uses the Windows Error Reporting to dump lsass","references":["https://github.com/deepinstinct/Lsass-Shtinkering","https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_werfault_lsass_shtinkering.yml","techniques":["T1003.001"],"cves":[]},{"id":"9bd012ee-0dff-44d7-84a0-aa698cfd87a3","title":"LSASS Memory Access by Tool With Dump Keyword In Name","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-10","modified":"2023-11-29","description":"Detects LSASS process access requests from a source process with the \"dump\" keyword in its image name.","references":["https://twitter.com/_xpn_/status/1491557187168178176","https://www.ired.team/offensive-security/credential-access-and-credential-dumping/dump-credentials-from-lsass-process-without-mimikatz"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0002"],"path":"rules/windows/process_access/proc_access_win_lsass_dump_keyword_image.yml","techniques":["T1003.001"],"cves":[]},{"id":"9f5c1d59-33be-4e60-bcab-85d2f566effd","title":"Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-27","modified":null,"description":"Detects suspicious process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace.\nThese DLLs contain functions like MiniDumpWriteDump that can be abused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll,\ndbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.\n","references":["https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html","https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpwritedump"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.defense-impairment","attack.t1003.001","attack.t1685"],"path":"rules/windows/process_access/proc_access_win_susp_dbgcore_dbghelp_load.yml","techniques":["T1003.001","T1685"],"cves":[]},{"id":"a0a278fe-2c0e-4de2-ac3c-c68b08a9ba98","title":"LSASS Access Detected via Attack Surface Reduction","author":"Markus Neis","status":"test","level":"high","date":"2018-08-26","modified":"2022-08-13","description":"Detects Access to LSASS Process","references":["https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/builtin/windefend/win_defender_asr_lsass_access.yml","techniques":["T1003.001"],"cves":[]},{"id":"a18dd26b-6450-46de-8c91-9659150cf088","title":"Potentially Suspicious GrantedAccess Flags On LSASS","author":"Florian Roth, Roberto Rodriguez, Dimitrios Slamaris, Mark Russinovich, Thomas Patzke, Teymur Kheirkhabarov, Sherif Eldeeb, James Dickenson, Aleksey Potapov, oscd.community","status":"test","level":"medium","date":"2021-11-22","modified":"2026-06-29","description":"Detects process access requests to LSASS process with potentially suspicious access flags","references":["https://learn.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights","https://onedrive.live.com/view.aspx?resid=D026B4699190F1E6!2843&ithint=file%2cpptx&app=PowerPoint&authkey=!AMvCRTKB_V1J5ow","https://web.archive.org/web/20230208123920/https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html","https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://web.archive.org/web/20230420013146/http://security-research.dyndns.org/pub/slides/FIRST2017/FIRST-2017_Tom-Ueltschi_Sysmon_FINAL_notes.pdf"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0002"],"path":"rules/windows/process_access/proc_access_win_lsass_susp_access_flag.yml","techniques":["T1003.001"],"cves":[]},{"id":"a18e0862-127b-43ca-be12-1a542c75c7c5","title":"LSASS Process Crashed - Application","author":"Nasreddine Bencherchali (Nextron Systems)","status":"experimental","level":"high","date":"2022-12-07","modified":"2025-12-03","description":"Detects Windows error reporting events where the process that crashed is LSASS (Local Security Authority Subsystem Service).\nThis could be the cause of a provoked crash by techniques such as Lsass-Shtinkering to dump credentials.\n","references":["https://github.com/deepinstinct/Lsass-Shtinkering","https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf","https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-erref/596a1078-e883-4972-9bbc-49e60bebca55"],"logsource":{"product":"windows","service":"application"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/builtin/application/application_error/win_application_error_lsass_crash.yml","techniques":["T1003.001"],"cves":[]},{"id":"a49fa4d5-11db-418c-8473-1e014a8dd462","title":"Lsass Memory Dump via Comsvcs DLL","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"high","date":"2020-10-20","modified":"2023-11-29","description":"Detects adversaries leveraging the MiniDump export function from comsvcs.dll via rundll32 to perform a memory dump from lsass.","references":["https://twitter.com/shantanukhande/status/1229348874298388484","https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_access/proc_access_win_lsass_dump_comsvcs_dll.yml","techniques":["T1003.001"],"cves":[]},{"id":"a5a2d357-1ab8-4675-a967-ef9990a59391","title":"LSASS Process Memory Dump Files","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-11-15","modified":"2024-10-08","description":"Detects creation of files with names used by different memory dumping tools to create a memory dump of the LSASS process memory, which contains user credentials.","references":["https://www.google.com/search?q=procdump+lsass","https://medium.com/@markmotig/some-ways-to-dump-lsass-exe-c4a75fdc49bf","https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/credential_access_lsass_memdump_file_created.toml","https://www.whiteoaksecurity.com/blog/attacks-defenses-dumping-lsass-no-mimikatz/","https://github.com/helpsystems/nanodump","https://github.com/CCob/MirrorDump","https://github.com/safedv/RustiveDump/blob/1a9b026b477587becfb62df9677cede619d42030/src/main.rs#L35","https://github.com/ricardojoserf/NativeDump/blob/01d8cd17f31f51f5955a38e85cd3c83a17596175/NativeDump/Program.cs#L258"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/file/file_event/file_event_win_lsass_default_dump_file_names.yml","techniques":["T1003.001"],"cves":[]},{"id":"a642964e-bead-4bed-8910-1bb4d63e3b4d","title":"HackTool - Mimikatz Execution","author":"Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton","status":"test","level":"high","date":"2019-10-22","modified":"2023-02-21","description":"Detection well-known mimikatz command line arguments","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://tools.thehacker.recipes/mimikatz/modules"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006"],"path":"rules/windows/process_creation/proc_creation_win_hktl_mimikatz_command_line.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006"],"cves":[]},{"id":"a6b33c02-8305-488f-8585-03cb2a7763f2","title":"Windows Credential Editor Registry","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2019-12-31","modified":"2021-11-27","description":"Detects the use of Windows Credential Editor (WCE)","references":["https://www.ampliasecurity.com/research/windows-credentials-editor/"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.credential-access","attack.t1003.001","attack.s0005"],"path":"rules/windows/registry/registry_event/registry_event_hack_wce_reg.yml","techniques":["T1003.001"],"cves":[]},{"id":"aa1697b7-d611-4f9a-9cb2-5125b4ccfd5c","title":"Password Dumper Activity on LSASS","author":"sigma","status":"test","level":"high","date":"2017-02-12","modified":"2022-10-09","description":"Detects process handle on LSASS process with certain access mask and object type SAM_DOMAIN","references":["https://twitter.com/jackcr/status/807385668833968128"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/builtin/security/win_security_susp_lsass_dump.yml","techniques":["T1003.001"],"cves":[]},{"id":"aa35a627-33fb-4d04-a165-d33b4afca3e8","title":"Remote LSASS Process Access Through Windows Remote Management","author":"Patryk Prauze - ING Tech","status":"stable","level":"high","date":"2019-05-20","modified":"2023-11-29","description":"Detects remote access to the LSASS process via WinRM. This could be a sign of credential dumping from tools like mimikatz.","references":["https://pentestlab.blog/2018/05/15/lateral-movement-winrm/"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1059.001","attack.lateral-movement","attack.t1021.006","attack.s0002"],"path":"rules/windows/process_access/proc_access_win_lsass_remote_access_trough_winrm.yml","techniques":["T1003.001","T1059.001","T1021.006"],"cves":[]},{"id":"b1876533-4ed5-4a83-90f3-b8645840a413","title":"HackTool - SafetyKatz Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"critical","date":"2022-10-20","modified":"2023-02-04","description":"Detects the execution of the hacktool SafetyKatz via PE information and default Image name","references":["https://github.com/GhostPack/SafetyKatz"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_safetykatz.yml","techniques":["T1003.001"],"cves":[]},{"id":"b1bd3a59-c1fd-4860-9f40-4dd161a7d1f5","title":"HackTool - HandleKatz Duplicating LSASS Handle","author":"Bhabesh Raj (rule), @thefLinkk","status":"test","level":"high","date":"2022-06-27","modified":"2023-11-28","description":"Detects HandleKatz opening LSASS to duplicate its handle to later dump the memory without opening any new handles","references":["https://github.com/codewhitesec/HandleKatz"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.execution","attack.t1106","attack.t1003.001","attack.credential-access"],"path":"rules/windows/process_access/proc_access_win_hktl_handlekatz_lsass_access.yml","techniques":["T1106","T1003.001"],"cves":[]},{"id":"b99a1518-1ad5-4f65-bc95-1ffff97a8fd0","title":"HackTool - Inveigh Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"critical","date":"2022-10-24","modified":"2023-02-04","description":"Detects the use of Inveigh a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool","references":["https://github.com/Kevin-Robertson/Inveigh","https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_inveigh.yml","techniques":["T1003.001"],"cves":[]},{"id":"bdc64095-d59a-42a2-8588-71fd9c9d9abc","title":"Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded","author":"Perez Diego (@darkquassar), oscd.community, Ecco","status":"test","level":"high","date":"2019-10-27","modified":"2022-12-09","description":"Detects the load of dbghelp/dbgcore DLL (used to make memory dumps) by suspicious processes.\nTools like ProcessHacker and some attacker tradecract use MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll.\nAs an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine.\n","references":["https://learn.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump","https://www.pinvoke.net/default.aspx/dbghelp/MiniDumpWriteDump.html","https://medium.com/@fsx30/bypass-edrs-memory-protection-introduction-to-hooking-2efb21acffd6"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/image_load/image_load_dll_dbghelp_dbgcore_unsigned_load.yml","techniques":["T1003.001"],"cves":[]},{"id":"c3e76af5-4ce0-4a14-9c9a-25ceb8fda182","title":"WerFault LSASS Process Memory Dump","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-06-27","modified":null,"description":"Detects WerFault creating a dump file with a name that indicates that the dump file could be an LSASS process memory, which contains user credentials","references":["https://github.com/helpsystems/nanodump"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/file/file_event/file_event_win_lsass_werfault_dump.yml","techniques":["T1003.001"],"cves":[]},{"id":"c8da0dfd-4ed0-4b68-962d-13c9c884384e","title":"Potential Credential Dumping Via LSASS Process Clone","author":"Florian Roth (Nextron Systems), Samir Bousseaden","status":"test","level":"critical","date":"2021-11-27","modified":"2023-03-02","description":"Detects a suspicious LSASS process process clone that could be a sign of credential dumping activity","references":["https://www.matteomalvica.com/blog/2019/12/02/win-defender-atp-cred-bypass/","https://twitter.com/Hexacorn/status/1420053502554951689","https://twitter.com/SBousseaden/status/1464566846594691073?s=20"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_lsass_process_clone.yml","techniques":["T1003","T1003.001"],"cves":[]},{"id":"ca621ba5-54ab-4035-9942-d378e6fcde3c","title":"HackTool - HandleKatz LSASS Dumper Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-08-18","modified":"2024-11-23","description":"Detects the use of HandleKatz, a tool that demonstrates the usage of cloned handles to Lsass in order to create an obfuscated memory dump of the same","references":["https://github.com/codewhitesec/HandleKatz"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_handlekatz.yml","techniques":["T1003.001"],"cves":[]},{"id":"d0d2f720-d14f-448d-8242-51ff396a334e","title":"HackTool - Generic Process Access","author":"Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel","status":"test","level":"high","date":"2023-11-27","modified":null,"description":"Detects process access requests from hacktool processes based on their default image name","references":["https://jsecurity101.medium.com/bypassing-access-mask-auditing-strategies-480fb641c158","https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0002"],"path":"rules/windows/process_access/proc_access_win_hktl_generic_access.yml","techniques":["T1003.001"],"cves":[]},{"id":"d474c8fe-bb69-4ea0-b7d9-f682b56d52d3","title":"HackTool - Doppelanger LSASS Dumper Execution","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-07-01","modified":null,"description":"Detects the execution of the Doppelanger hacktool which is used to dump LSASS memory via process cloning while evading common detection methods","references":["https://labs.yarix.com/2025/06/doppelganger-an-advanced-lsass-dumper-with-process-cloning/","https://github.com/vari-sh/RedTeamGrimoire/tree/668e0357072546065729ad623f8c02f7be21bb08/Doppelganger"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_doppelganger.yml","techniques":["T1003.001"],"cves":[]},{"id":"dee0a7a3-f200-4112-a99b-952196d81e42","title":"DumpMinitool Execution","author":"Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-04-06","modified":"2023-04-12","description":"Detects the use of \"DumpMinitool.exe\" a tool that allows the dump of process memory via the use of the \"MiniDumpWriteDump\"","references":["https://twitter.com/mrd0x/status/1511415432888131586","https://twitter.com/mrd0x/status/1511489821247684615","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/","https://gist.github.com/nasbench/6d58c3c125e2fa1b8f7a09754c1b087f"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036","attack.t1003.001","attack.credential-access"],"path":"rules/windows/process_creation/proc_creation_win_dumpminitool_execution.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"e074832a-eada-4fd7-94a1-10642b130e16","title":"HackTool - SafetyKatz Dump Indicator","author":"Markus Neis","status":"test","level":"high","date":"2018-07-24","modified":"2024-06-27","description":"Detects default lsass dump filename generated by SafetyKatz.","references":["https://github.com/GhostPack/SafetyKatz","https://github.com/GhostPack/SafetyKatz/blob/715b311f76eb3a4c8d00a1bd29c6cd1899e450b7/SafetyKatz/Program.cs#L63"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/file/file_event/file_event_win_hktl_safetykatz.yml","techniques":["T1003.001"],"cves":[]},{"id":"e5b33f7d-eb93-48b6-9851-09e1e610b6d7","title":"Credential Dumping Attempt Via WerFault","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2012-06-27","modified":"2023-11-29","description":"Detects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up.","references":["https://github.com/helpsystems/nanodump/commit/578116faea3d278d53d70ea932e2bbfe42569507"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0002"],"path":"rules/windows/process_access/proc_access_win_lsass_werfault.yml","techniques":["T1003.001"],"cves":[]},{"id":"e76c8240-d68f-4773-8880-5c6f63595aaf","title":"Time Travel Debugging Utility Usage - Image","author":"Ensar Şamil, @sblmsrsn, @oscd_initiative","status":"test","level":"high","date":"2020-10-06","modified":"2022-12-02","description":"Detects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.","references":["https://lolbas-project.github.io/lolbas/Binaries/Tttracer/","https://twitter.com/mattifestation/status/1196390321783025666","https://twitter.com/oulusoyum/status/1191329746069655553"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.credential-access","attack.stealth","attack.t1218","attack.t1003.001"],"path":"rules/windows/image_load/image_load_dll_tttracer_module_load.yml","techniques":["T1218","T1003.001"],"cves":[]},{"id":"eb1c4225-1c23-4241-8dd4-051389fde4ce","title":"Suspicious DumpMinitool Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-06","modified":"2023-04-12","description":"Detects suspicious ways to use the \"DumpMinitool.exe\" binary","references":["https://twitter.com/mrd0x/status/1511415432888131586","https://twitter.com/mrd0x/status/1511489821247684615","https://lolbas-project.github.io/lolbas/OtherMSBinaries/DumpMinitool/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.stealth","attack.t1036","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_dumpminitool_susp_execution.yml","techniques":["T1036","T1003.001"],"cves":[]},{"id":"edadb1e5-5919-4e4c-8462-a9e643b02c4b","title":"Process Memory Dump via RdrLeakDiag.EXE","author":"Cedric MAURUGEON, Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-09-24","modified":"2024-08-15","description":"Detects the use of the Microsoft Windows Resource Leak Diagnostic tool \"rdrleakdiag.exe\" to dump process memory","references":["https://www.pureid.io/dumping-abusing-windows-credentials-part-1/","https://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/","https://lolbas-project.github.io/lolbas/Binaries/Rdrleakdiag/","https://twitter.com/0gtweet/status/1299071304805560321?s=21","https://news.sophos.com/en-us/2024/06/05/operation-crimson-palace-a-technical-deep-dive"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_rdrleakdiag_process_dumping.yml","techniques":["T1003.001"],"cves":[]},{"id":"f0d1feba-4344-4ca9-8121-a6c97bd6df52","title":"Credential Dumping Tools Service Execution - Security","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/security/win_security_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"f239b326-2f41-4d6b-9dfa-c846a60ef505","title":"Password Dumper Remote Thread in LSASS","author":"Thomas Patzke","status":"stable","level":"high","date":"2017-02-19","modified":"2021-06-21","description":"Detects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage.\nThe process in field Process is the malicious program. A single execution can lead to hundreds of events.\n","references":["https://jpcertcc.github.io/ToolAnalysisResultSheet/details/WCE.htm"],"logsource":{"product":"windows","category":"create_remote_thread"},"tags":["attack.credential-access","attack.s0005","attack.t1003.001"],"path":"rules/windows/create_remote_thread/create_remote_thread_win_susp_password_dumper_lsass.yml","techniques":["T1003.001"],"cves":[]},{"id":"f26307d8-14cd-47e3-a26b-4b4769f24af6","title":"HackTool - CrackMapExec Process Patterns","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-03-12","modified":"2023-02-13","description":"Detects suspicious process patterns found in logs when CrackMapExec is used","references":["https://mpgn.gitbook.io/crackmapexec/smb-protocol/obtaining-credentials/dump-lsass"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_patterns.yml","techniques":["T1003.001"],"cves":[]},{"id":"f8be3e82-46a3-4e4e-ada5-8e538ae8b9c9","title":"Credential Dumping Activity By Python Based Tool","author":"Bhabesh Raj, Jonhnathan Ribeiro","status":"stable","level":"high","date":"2023-11-27","modified":"2023-11-29","description":"Detects LSASS process access for potential credential dumping by a Python-like tool such as LaZagne or Pypykatz.","references":["https://twitter.com/bh4b3sh/status/1303674603819081728","https://github.com/skelsec/pypykatz"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0349"],"path":"rules/windows/process_access/proc_access_win_lsass_python_based_tool.yml","techniques":["T1003.001"],"cves":[]},{"id":"fa34b441-961a-42fa-a100-ecc28c886725","title":"LSASS Access From Program In Potentially Suspicious Folder","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2021-11-27","modified":"2023-12-06","description":"Detects process access to LSASS memory with suspicious access flags and from a potentially suspicious folder","references":["https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights","https://onedrive.live.com/view.aspx?resid=D026B4699190F1E6!2843&ithint=file%2cpptx&app=PowerPoint&authkey=!AMvCRTKB_V1J5ow","https://web.archive.org/web/20230208123920/https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html","https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment","https://web.archive.org/web/20230420013146/http://security-research.dyndns.org/pub/slides/FIRST2017/FIRST-2017_Tom-Ueltschi_Sysmon_FINAL_notes.pdf"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.credential-access","attack.t1003.001","attack.s0002","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_access/proc_access_win_lsass_susp_source_process.yml","techniques":["T1003.001"],"cves":[]},{"id":"fb656378-f909-47c1-8747-278bf09f4f4f","title":"Potential Credential Dumping Attempt Via PowerShell Remote Thread","author":"oscd.community, Natalia Shornikova","status":"test","level":"high","date":"2020-10-06","modified":"2022-12-18","description":"Detects remote thread creation by PowerShell processes into \"lsass.exe\"","references":["https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse"],"logsource":{"product":"windows","category":"create_remote_thread"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/create_remote_thread/create_remote_thread_win_powershell_lsass.yml","techniques":["T1003.001"],"cves":[]},{"id":"ffa6861c-4461-4f59-8a41-578c39f3f23e","title":"LSASS Dump Keyword In CommandLine","author":"E.M. Anhaus, Tony Lambert, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2019-10-24","modified":"2023-08-29","description":"Detects the presence of the keywords \"lsass\" and \".dmp\" in the commandline, which could indicate a potential attempt to dump or create a dump of the lsass process.\n","references":["https://github.com/Hackndo/lsassy","https://medium.com/@markmotig/some-ways-to-dump-lsass-exe-c4a75fdc49bf","https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/credential_access_lsass_memdump_file_created.toml","https://www.whiteoaksecurity.com/blog/attacks-defenses-dumping-lsass-no-mimikatz/","https://github.com/helpsystems/nanodump","https://github.com/CCob/MirrorDump"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1003.001"],"path":"rules/windows/process_creation/proc_creation_win_susp_lsass_dmp_cli_keywords.yml","techniques":["T1003.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-32706","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2025-32701","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-4577","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-26360","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}