LSASS Process Dump Artefact In CrashDumps Folder

 Original Source: [Sigma source]
Title: LSASS Process Dump Artefact In CrashDumps Folder
Status: test
Description:Detects the presence of an LSASS dump file in the "CrashDumps" folder. This could be a sign of LSASS credential dumping. Techniques such as the LSASS Shtinkering have been seen abusing the Windows Error Reporting to dump said process.
References:
  -https://github.com/deepinstinct/Lsass-Shtinkering
  -https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf
Author: @pbssubhash
Date: 2022-12-08
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|startswith: 'C:\Windows\System32\config\systemprofile\AppData\Local\CrashDumps\'
    TargetFilename|contains: 'lsass.exe.'
    TargetFilename|endswith: '.dmp'
  condition:selection
Falsepositives:
  -Rare legitimate dump of the process by the operating system due to a crash of lsass
Level: high