Credential Dumping Tools Service Execution - Security

 Original Source: [Sigma source]
Title: Credential Dumping Tools Service Execution - Security
Status: test
Description:Detects well-known credential dumping tools execution via service execution events
References:
  -https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
Author: Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community
Date: 2017-03-05
modified:2022-11-29
Tags:
  • -'attack.credential-access'
  • -'attack.execution'
  • -'attack.t1003.001'
  • -'attack.t1003.002'
  • -'attack.t1003.004'
  • -'attack.t1003.005'
  • -'attack.t1003.006'
  • -'attack.t1569.002'
  • -'attack.s0005'
Logsource:
  • product: windows
  • service: security
  • definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
Detection:
  selection:
    EventID: '4697'
    ServiceFileName|contains:
      -'cachedump'
      -'dumpsvc'
      -'fgexec'
      -'gsecdump'
      -'mimidrv'
      -'pwdump'
      -'servpw'

  condition:selection
Falsepositives:
  -Legitimate Administrator using credential dumping tool for password recovery
Level: high