LoFP LoFP / legitimate administrator using credential dumping tool for password recovery

Techniques

Sample rules

Credential Dumping Tools Service Execution - Security

Description

Detects well-known credential dumping tools execution via service execution events

Detection logic

condition: selection
selection:
  EventID: 4697
  ServiceFileName|contains:
  - cachedump
  - dumpsvc
  - fgexec
  - gsecdump
  - mimidrv
  - pwdump
  - servpw

Credential Dumping Tools Service Execution - System

Description

Detects well-known credential dumping tools execution via service execution events

Detection logic

condition: selection
selection:
  EventID: 7045
  ImagePath|contains:
  - cachedump
  - dumpsvc
  - fgexec
  - gsecdump
  - mimidrv
  - pwdump
  - servpw
  Provider_Name: Service Control Manager