Techniques
Sample rules
Windows Possible Credential Dumping
- source: splunk
- technicques:
Description
The following analytic detects possible credential dumping by identifying suspicious process access to LSASS with credential-dumping-related call traces. It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_QUERY_LIMITED_INFORMATION (0x1000) and PROCESS_DUP_HANDLE (0x40).
Detection logic
`sysmon`
EventCode=10
TargetImage=*\\lsass.exe
CallTrace IN (
"*dbgcore.dll*",
"*dbghelp.dll*",
"*kernel32.dll*",
"*kernelbase.dll*",
"*ntdll.dll*"
)
NOT SourceUser IN (
"NT AUTHORITY\\SYSTEM",
"NT AUTHORITY\\NETWORK SERVICE"
)
We looking for a value of PROCESS_QUERY_LIMITED_INFORMATION (0x1000) or PROCESS_DUP_HANDLE (0x40).
| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096
| eval PROCESS_DUP_HANDLE = 64
| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)
| eval duplicate_handle_set = bit_and(g_access_decimal, PROCESS_DUP_HANDLE)
| where query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION
OR duplicate_handle_set == PROCESS_DUP_HANDLE
| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product
| eval CallTrace=split(CallTrace, "
|")
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_possible_credential_dumping_filter`