LoFP LoFP / false positives will occur when legitimate tools request query-limited or duplicate-handle access to lsass. filter based on source image as needed. cobalt strike usage of mimikatz may generate this activity.

Techniques

Sample rules

Windows Possible Credential Dumping

Description

The following analytic detects possible credential dumping by identifying suspicious process access to LSASS with credential-dumping-related call traces. It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_LIMITED_INFORMATION (0x1000) and PROCESS_DUP_HANDLE (0x40).

Detection logic

`sysmon`
EventCode=10
TargetImage=*\\lsass.exe
CallTrace IN (
    "*dbgcore.dll*",
    "*dbghelp.dll*",
    "*kernel32.dll*",
    "*kernelbase.dll*",
    "*ntdll.dll*"
)
NOT SourceUser IN (
    "NT AUTHORITY\\SYSTEM",
    "NT AUTHORITY\\NETWORK SERVICE"
)

We looking for a value of PROCESS_QUERY_LIMITED_INFORMATION (0x1000) or PROCESS_DUP_HANDLE (0x40).


| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)

| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096

| eval PROCESS_DUP_HANDLE = 64

| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)

| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)

| where query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION
  OR duplicate_handle_set == PROCESS_DUP_HANDLE


| stats count min(_time) as firstTime
                max(_time) as lastTime
    BY user_id dest
       signature_id signature granted_access Opcode
       SourceImage SourceProcessGUID SourceProcessId
       TargetImage TargetProcessGUID TargetProcessId
       CallTrace vendor_product


| eval CallTrace=split(CallTrace, "
|")


| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `windows_possible_credential_dumping_filter`