Title:
Potential SysInternals ProcDump Evasion
Status:
test
Description:Detects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name
References:
-https://twitter.com/mrd0x/status/1480785527901204481
Author: Florian Roth (Nextron Systems)
Date: 2022-01-11
modified:2023-05-09
Tags:
- -'attack.stealth'
- -'attack.t1036'
- -'attack.t1003.001'
- -'attack.credential-access'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_1:
CommandLine|contains:
-'copy procdump'
-'move procdump'
selection_2:
CommandLine|contains|all:
-'copy '
-'.dmp '
CommandLine|contains:
-'2.dmp'
-'lsass'
-'out.dmp'
selection_3:
CommandLine|contains:
-'copy lsass.exe_'
-'move lsass.exe_'
condition:
1 of selection_*
Falsepositives:
-False positives are expected in cases in which ProcDump just gets copied to a different directory without any renaming
Level:
high