Title:
Credential Dumping Attempt Via WerFault
Status:
test
Description:Detects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up.
References:
-https://github.com/helpsystems/nanodump/commit/578116faea3d278d53d70ea932e2bbfe42569507
Author: Florian Roth (Nextron Systems)
Date: 2022-06-27
modified:2023-11-29
Tags:
- -'attack.credential-access'
- -'attack.t1003.001'
- -'attack.s0002'
Logsource:
- category: process_access
- product: windows
Detection:
selection:
SourceImage|endswith:
'\WerFault.exe'
TargetImage|endswith:
'\lsass.exe'
GrantedAccess:
'0x1FFFFF'
condition:
selection
Falsepositives:
-Actual failures in lsass.exe that trigger a crash dump (unlikely)
-Unknown cases in which WerFault accesses lsass.exe
Level:
high