This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PPL Tampering Via WerFaultSecure
Original Source:
[Sigma source]
Title:
PPL Tampering Via WerFaultSecure
Status:
experimental
Description:
Detects potential abuse of WerFaultSecure.exe to dump Protected Process Light (PPL) processes like LSASS or to freeze security solutions (EDR/antivirus). This technique is used by tools such as EDR-Freeze and WSASS to bypass PPL protections and access sensitive information or disable security software. Distinct command line patterns help identify the specific tool: - WSASS usage typically shows: "WSASS.exe WerFaultSecure.exe [PID]" in ParentCommandLine - EDR-Freeze usage typically shows: "EDR-Freeze_[version].exe [PID] [timeout]" in ParentCommandLine Legitimate debugging operations using WerFaultSecure are rare in production environments and should be investigated.
References:
-https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html
-https://github.com/TwoSevenOneT/EDR-Freeze/blob/a7f61030b36fbde89871f393488f7075d2aa89f6/EDR-Freeze.cpp#L53
-https://www.zerosalarium.com/2025/09/Dumping-LSASS-With-WER-On-Modern-Windows-11.html
-https://github.com/TwoSevenOneT/WSASS/blob/2c8fd9fa32143e7bc9f066e9511c6f8a57bc64b5/WSASS.cpp#L251
Author:
Jason (https://github.com/0xbcf)
Date:
2025-09-23
modified:
2025-11-23
Tags:
-'attack.defense-impairment'
-'attack.t1685'
-'attack.credential-access'
-'attack.t1003.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_image:
Image|endswith
:
'\WerFaultSecure.exe'
OriginalFileName
:
'WerFaultSecure.exe'
selection_args:
CommandLine|contains|all
:
-' /h '
-' /pid '
-' /tid '
-' /encfile '
-' /cancel '
-' /type '
-' 268310'
condition
:
all of selection_*
Falsepositives:
-Legitimate usage of WerFaultSecure for debugging purposes
Level:
high