Remote LSASS Process Access Through Windows Remote Management

 Original Source: [Sigma source]
Title: Remote LSASS Process Access Through Windows Remote Management
Status: stable
Description:Detects remote access to the LSASS process via WinRM. This could be a sign of credential dumping from tools like mimikatz.
References:
  -https://pentestlab.blog/2018/05/15/lateral-movement-winrm/
Author: Patryk Prauze - ING Tech
Date: 2019-05-20
modified:2023-11-29
Tags:
  • -'attack.credential-access'
  • -'attack.execution'
  • -'attack.t1003.001'
  • -'attack.t1059.001'
  • -'attack.lateral-movement'
  • -'attack.t1021.006'
  • -'attack.s0002'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    TargetImage|endswith: '\lsass.exe'
    SourceImage|endswith: ':\Windows\system32\wsmprovhost.exe'
  filter_main_access:
    GrantedAccess: '0x80000000'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unlikely
Level: high