LoFP LoFP / t1036

t1036

TitleTags
administrative activity
administrative activity (adjust code pages according to your organization's region)
administrators who rename binaries (should be investigated).
another tool that uses command line flags similar to procdump
another tool that uses the command line switches of xordump
citrix
command lines that use the same flags
commandlines that contains scriptures such as arabic or hebrew might make use of this character
commandlines with legitimate cyrillic text; will likely require tuning (or not be usable) in countries where these alphabets are in use.
custom applications use renamed binaries adding slight change to binary name. typically this is easy to spot and add to whitelist
custom windows error reporting debugger or applications restarted by werfault after a crash.
depend on scripts and administrative tools used in the monitored environment (for example an admin scripts like https://www.itexperience.net/sccm-batch-files-and-32-bits-processes-on-64-bits-os/)
directories /dev/shm and /run/shm are temporary file storage directories in linux. they are intended to appear as a mounted file system, but uses virtual memory instead of a persistent storage device and thus are used for mounting file systems in legitimate purposes.
false positives are expected in cases in which procdump just gets copied to a different directory without any renaming
false positives depend on scripts and administrative tools used in the monitored environment
false-positives (fp) can appear if the pid file is legitimate and holding a process id as intended. to differentiate, if the pid file is an executable or larger than 10 bytes, it should be ruled suspicious.
false-positives (fp) should be at a minimum with this detection as pid files are meant to hold process ids, not inherently be executables that spawn processes.
file names with legitimate cyrillic text. will likely require tuning (or not be usable) in countries where these alphabets are in use.
filenames that contains scriptures such as arabic or hebrew might make use of this character
google drive
installers and updaters may set currently in use files for rename or deletion after a reboot.
legit application crash with rare werfault commandline value
legitimate administrative actions using mmc to execute misnamed `.msc` files.
legitimate powershell scripts
legitimate software that uses these patterns
legitimate system administration tasks scheduling trusted system processes.
legitimate use of procdump by a developer or administrator
legitimate use of the tool by administrators or users to update metadata of a binary
legitimate used of encrypted zip files
microsoft antimalware service executable installed on non default installation path.
mistyped commands or legitimate binaries named to match the pattern
procdump illegally bundled with legitimate software.
psexec installed via windows store doesn't contain original filename field (false negative)
russian speaking people changing the codepage
some legitimate apps use this, but limited.
some security products seem to spawn these
some tuning is required for other general purpose directories of third party apps
system components such as daemon-set-controller and kube-scheduler also create pods in the kube-system namespace
system processes copied outside their default folders for testing purposes
the build engine is commonly used by windows developers but use by non-engineers is unusual.
third party software might bundle specific versions of system dlls.
third party software naming their software with the same names as the processes mentioned here
this is meant to run only on datasources using elastic agent 7.14+ since versions prior to that will be missing the necessary field, resulting in false positives.
unconventional but non-malicious usage of rlo or reversed extensions.
unknown
unknown flash download locations
unlikely
unlikely, because no one should dump an lsass process memory
vscode extensions or similar legitimate tools might use unsigned .node files. these should be investigated on a case-by-case basis, and whitelisted if determined to be benign.
when cmd.exe and xcopy.exe are called directly
when the command contains the keywords but not in the correct order