This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Process Memory Dump Via Comsvcs.DLL
Original Source:
[Sigma source]
Title:
Process Memory Dump Via Comsvcs.DLL
Status:
test
Description:
Detects a process memory dump via "comsvcs.dll" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)
References:
-https://twitter.com/shantanukhande/status/1229348874298388484
-https://twitter.com/pythonresponder/status/1385064506049630211?s=21
-https://twitter.com/Hexacorn/status/1224848930795552769
-https://modexp.wordpress.com/2019/08/30/minidumpwritedump-via-com-services-dll/
-https://twitter.com/SBousseaden/status/1167417096374050817
-https://twitter.com/Wietze/status/1542107456507203586
-https://github.com/Hackndo/lsassy/blob/14d8f8ae596ecf22b449bfe919829173b8a07635/lsassy/dumpmethod/comsvcs.py
-https://www.youtube.com/watch?v=52tAmVLg1KM&t=2070s
Author:
Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
Date:
2020-02-18
modified:
2025-02-23
Tags:
-'attack.credential-access'
-'attack.stealth'
-'attack.t1036'
-'attack.t1003.001'
-'car.2013-05-009'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\rundll32.exe'
OriginalFileName
:
'RUNDLL32.EXE'
CommandLine|contains
:
'rundll32'
selection_cli_1:
CommandLine|contains|all
:
-'comsvcs'
-'full'
CommandLine|contains
:
-'#-'
-'#+'
-'#24'
-'24 '
-'MiniDump'
-'#65560'
selection_generic:
CommandLine|contains|all
:
-'24'
-'comsvcs'
-'full'
CommandLine|contains
:
-' #'
-',#'
-', #'
-'"#'
condition
:
(selection_img and 1 of selection_cli_*) or selection_generic
Falsepositives:
-Unlikely
Level:
high