Suspicious Kernel Dump Using Dtrace

 Original Source: [Sigma source]
Title: Suspicious Kernel Dump Using Dtrace
Status: test
Description:Detects suspicious way to dump the kernel on Windows systems using dtrace.exe, which is available on Windows systems since Windows 10 19H1
References:
  -https://twitter.com/0gtweet/status/1474899714290208777?s=12
  -https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/dtrace
Author: Florian Roth (Nextron Systems)
Date: 2021-12-28
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.t1082'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_plain:
    Image|endswith: '\dtrace.exe'
    CommandLine|contains: 'lkd(0)'
  selection_obfuscated:
    CommandLine|contains|all:
      -'syscall:::return'
      -'lkd('

  condition:1 of selection*
Falsepositives:
  -Unknown
Level: high