Credential Dumping Attempt Via WerFault

 Original Source: [Sigma source]
Title: Credential Dumping Attempt Via WerFault
Status: test
Description:Detects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up.
References:
  -https://github.com/helpsystems/nanodump/commit/578116faea3d278d53d70ea932e2bbfe42569507
Author: Florian Roth (Nextron Systems)
Date: 2022-06-27
modified:2023-11-29
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
  • -'attack.s0002'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    SourceImage|endswith: '\WerFault.exe'
    TargetImage|endswith: '\lsass.exe'
    GrantedAccess: '0x1FFFFF'
  condition:selection
Falsepositives:
  -Actual failures in lsass.exe that trigger a crash dump (unlikely)
  -Unknown cases in which WerFault accesses lsass.exe
Level: high