Title:Remote LSASS Process Access Through Windows Remote Management Status:stable Description:Detects remote access to the LSASS process via WinRM. This could be a sign of credential dumping from tools like mimikatz. References: -https://pentestlab.blog/2018/05/15/lateral-movement-winrm/ Author: Patryk Prauze - ING Tech Date: 2019-05-20 modified:2023-11-29 Tags:
-'attack.credential-access'
-'attack.execution'
-'attack.t1003.001'
-'attack.t1059.001'
-'attack.lateral-movement'
-'attack.t1021.006'
-'attack.s0002'
Logsource:
category: process_access
product: windows
Detection: selection: TargetImage|endswith:
'\lsass.exe' SourceImage|endswith:
':\Windows\system32\wsmprovhost.exe' filter_main_access: GrantedAccess:
'0x80000000' condition:selection and not 1 of filter_main_* Falsepositives:
-Unlikely Level:high