LoFP LoFP / the activity may be legitimate. other tools can access lsass for legitimate reasons, and it's possible this event could be generated in those cases. in these cases, false positives should be fairly obvious and you may need to tweak the search to eliminate noise.

Techniques

Sample rules

Detect Credential Dumping through LSASS access

Description

The following analytic detects attempts to read LSASS memory, indicative of credential dumping. It leverages Sysmon EventCode 10 and checks for “PROCESS_VM_READ” with query information access on lsass.exe.

Detection logic

`sysmon`
EventCode=10
TargetImage="*\\lsass.exe"

Convert GrantedAccess from hexadecimal to decimal. Match “PROCESS_VM_READ” with either “PROCESS_QUERY_LIMITED_INFORMATION” or “PROCESS_QUERY_INFORMATION”, which represent the either the “0x1010” or “0x1410” hexadecimal masks.


| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)

| eval PROCESS_VM_READ = 16

| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096

| eval PROCESS_QUERY_INFORMATION = 1024

| eval vm_read_set = bit_and(g_access_decimal, PROCESS_VM_READ)

| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)

| eval query_information_set = bit_and(g_access_decimal, PROCESS_QUERY_INFORMATION)

| where vm_read_set == PROCESS_VM_READ
  AND query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION
  AND (query_information_set == 0 OR query_information_set == PROCESS_QUERY_INFORMATION)


| stats count min(_time) as firstTime
                max(_time) as lastTime
    BY user_id dest
       signature_id signature granted_access Opcode
       SourceImage SourceProcessGUID SourceProcessId
       TargetImage TargetProcessGUID TargetProcessId
       CallTrace vendor_product


| eval CallTrace=split(CallTrace, "
|")


| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `detect_credential_dumping_through_lsass_access_filter`