Potential Credential Dumping Via LSASS Process Clone

 Original Source: [Sigma source]
Title: Potential Credential Dumping Via LSASS Process Clone
Status: test
Description:Detects a suspicious LSASS process process clone that could be a sign of credential dumping activity
References:
  -https://www.matteomalvica.com/blog/2019/12/02/win-defender-atp-cred-bypass/
  -https://twitter.com/Hexacorn/status/1420053502554951689
  -https://twitter.com/SBousseaden/status/1464566846594691073?s=20
Author: Florian Roth (Nextron Systems), Samir Bousseaden
Date: 2021-11-27
modified:2023-03-02
Tags:
  • -'attack.credential-access'
  • -'attack.t1003'
  • -'attack.t1003.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\Windows\System32\lsass.exe'
    Image|endswith: '\Windows\System32\lsass.exe'
  condition:selection
Falsepositives:
  -Unknown
Level: critical