LSASS Dump Keyword In CommandLine

 Original Source: [Sigma source]
Title: LSASS Dump Keyword In CommandLine
Status: test
Description:Detects the presence of the keywords "lsass" and ".dmp" in the commandline, which could indicate a potential attempt to dump or create a dump of the lsass process.
References:
  -https://github.com/Hackndo/lsassy
  -https://medium.com/@markmotig/some-ways-to-dump-lsass-exe-c4a75fdc49bf
  -https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/credential_access_lsass_memdump_file_created.toml
  -https://www.whiteoaksecurity.com/blog/attacks-defenses-dumping-lsass-no-mimikatz/
  -https://github.com/helpsystems/nanodump
  -https://github.com/CCob/MirrorDump
Author: E.M. Anhaus, Tony Lambert, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Date: 2019-10-24
modified:2023-08-29
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    - CommandLine|contains:
      - 'lsass.dmp'
      - 'lsass.zip'
      - 'lsass.rar'
      - 'Andrew.dmp'
      - 'Coredump.dmp'
      - 'NotLSASS.zip'
      - 'lsass_2'
      - 'lsassdump'
      - 'lsassdmp'
    - CommandLine|contains|all:
      - 'lsass'
      - '.dmp'
    - CommandLine|contains|all:
      - 'SQLDmpr'
      - '.mdmp'
    - CommandLine|contains|all:
      - 'nanodump'
      - '.dmp'
  condition:selection
Falsepositives:
  -Unlikely
Level: high