Password Dumper Remote Thread in LSASS

 Original Source: [Sigma source]
Title: Password Dumper Remote Thread in LSASS
Status: stable
Description:Detects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage. The process in field Process is the malicious program. A single execution can lead to hundreds of events.
References:
  -https://jpcertcc.github.io/ToolAnalysisResultSheet/details/WCE.htm
Author: Thomas Patzke
Date: 2017-02-19
modified:2021-06-21
Tags:
  • -'attack.credential-access'
  • -'attack.s0005'
  • -'attack.t1003.001'
Logsource:
  • product: windows
  • category: create_remote_thread
Detection:
  selection:
    TargetImage|endswith: '\lsass.exe'
    StartModule: ''
  condition:selection
Falsepositives:
  -Antivirus products
Level: high