Credential Dumping Attempt Via Svchost

 Original Source: [Sigma source]
Title: Credential Dumping Attempt Via Svchost
Status: test
Description:Detects when a process tries to access the memory of svchost to potentially dump credentials.
References:
  -Internal Research
Author: Florent Labouyrie
Date: 2021-04-30
modified:2022-10-09
Tags:
  • -'attack.privilege-escalation'
  • -'attack.t1548'
Logsource:
  • product: windows
  • category: process_access
Detection:
  selection:
    TargetImage|endswith: '\svchost.exe'
    GrantedAccess: '0x143a'
  filter_main_known_processes:
    SourceImage|endswith:
      -'\services.exe'
      -'\msiexec.exe'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high