Techniques
Sample rules
Detect Credential Dumping through LSASS access
- source: splunk
- technicques:
Description
The following analytic detects attempts to read LSASS memory, indicative of credential dumping. It leverages Sysmon EventCode 10 and checks for “PROCESS_VM_READ” with query information access on lsass.exe.
Detection logic
`sysmon`
EventCode=10
TargetImage="*\\lsass.exe"
Convert GrantedAccess from hexadecimal to decimal. Match “PROCESS_VM_READ” with either “PROCESS_QUERY_LIMITED_INFORMATION” or “PROCESS_QUERY_INFORMATION”, which represent the either the “0x1010” or “0x1410” hexadecimal masks.
| eval g_access_decimal = tonumber(replace(GrantedAccess,"0x",""),16)
| eval PROCESS_VM_READ = 16
| eval PROCESS_QUERY_LIMITED_INFORMATION = 4096
| eval PROCESS_QUERY_INFORMATION = 1024
| eval vm_read_set = bit_and(g_access_decimal, PROCESS_VM_READ)
| eval query_limited_set = bit_and(g_access_decimal, PROCESS_QUERY_LIMITED_INFORMATION)
| eval query_information_set = bit_and(g_access_decimal, PROCESS_QUERY_INFORMATION)
| where vm_read_set == PROCESS_VM_READ
AND query_limited_set == PROCESS_QUERY_LIMITED_INFORMATION
AND (query_information_set == 0 OR query_information_set == PROCESS_QUERY_INFORMATION)
| stats count min(_time) as firstTime
max(_time) as lastTime
BY user_id dest
signature_id signature granted_access Opcode
SourceImage SourceProcessGUID SourceProcessId
TargetImage TargetProcessGUID TargetProcessId
CallTrace vendor_product
| eval CallTrace=split(CallTrace, "
|")
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `detect_credential_dumping_through_lsass_access_filter`