From 9b010033d52d56e5d0da995d180486ddaac1a163 Mon Sep 17 00:00:00 2001 From: NovaSky Date: Mon, 30 Mar 2026 16:29:09 -0400 Subject: [PATCH] feat(chokepoint): add LSASS Credential Dumping (T1003.001) New chokepoint covering the kernel-mediated handle request to lsass.exe, the invariant prerequisite for all credential dumping tools. - Chokepoint YAML with 3 stages, 24 variations, 7 evolution timeline entries - Research sigma rule: baseline all non-system LSASS access (process_access) - Hunt sigma rule: CallTrace + source path behavioral filtering - Analyst sigma rule: triple-AND (access mask + dump mechanism + non-standard path) - Emulation script with SeDebugPrivilege handling and PPL detection - 4 raw log samples, 6 OSINT pivots, CHANGELOG updated --- CHANGELOG.md | 14 +- .../lsass-credential-dumping.yml | 657 ++++++++++++++++++ .../lsass-credential-dumping/emulate.ps1 | 240 +++++++ .../lsass-credential-dumping/analyst.yml | 82 +++ sigma-rules/lsass-credential-dumping/hunt.yml | 94 +++ .../lsass-credential-dumping/research.yml | 58 ++ 6 files changed, 1144 insertions(+), 1 deletion(-) create mode 100644 chokepoints/credential-access/lsass-credential-dumping.yml create mode 100644 emulation/lsass-credential-dumping/emulate.ps1 create mode 100644 sigma-rules/lsass-credential-dumping/analyst.yml create mode 100644 sigma-rules/lsass-credential-dumping/hunt.yml create mode 100644 sigma-rules/lsass-credential-dumping/research.yml diff --git a/CHANGELOG.md b/CHANGELOG.md index 635af60..439ec3b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,7 +2,19 @@ All notable changes to this detection chokepoints repository will be documented in this file. -## [2025-02-28] — LOLBAS-Style Restructuring +## [2026-03-30] - LSASS Credential Dumping Chokepoint + +### Added +- `chokepoints/credential-access/lsass-credential-dumping.yml` - New chokepoint: LSASS credential dumping (T1003.001) +- `sigma-rules/lsass-credential-dumping/research.yml` - Research-level Sigma rule (baseline all non-system LSASS access via process_access) +- `sigma-rules/lsass-credential-dumping/hunt.yml` - Hunt-level Sigma rule (CallTrace + source path behavioral filtering) +- `sigma-rules/lsass-credential-dumping/analyst.yml` - Analyst-level Sigma rule (triple-AND: access mask + dump mechanism + non-standard source) +- `emulation/lsass-credential-dumping/emulate.ps1` - PowerShell emulation script with SeDebugPrivilege handling and PPL detection +- 24 tool variations tracked (Mimikatz, comsvcs.dll, nanodump, HandleKatz, Cobalt Strike, Sliver, Havoc, Brute Ratel, Mythic, and more) +- 4 raw log samples (EID 10 classic, EID 10 direct syscall, EID 10 handle duplication, EID 1 comsvcs LOLBin) +- 6 OSINT pivot queries (VirusTotal, GitHub, LOLDrivers, ANY.RUN) + +## [2025-02-28] - LOLBAS-Style Restructuring ### Added - `CONTRIBUTING.md` — full contribution guide (schema requirements, PR checklist, what not to submit) diff --git a/chokepoints/credential-access/lsass-credential-dumping.yml b/chokepoints/credential-access/lsass-credential-dumping.yml new file mode 100644 index 0000000..12b1e75 --- /dev/null +++ b/chokepoints/credential-access/lsass-credential-dumping.yml @@ -0,0 +1,657 @@ +Name: LSASS Credential Dumping +Id: c7df4fc6-05da-4a67-8dfa-efcd8e2420e2 +MitreIds: + - T1003.001 + - T1003 + - T1547.005 +Tactics: + - Credential Access +Techniques: + - 'OS Credential Dumping: LSASS Memory' + - OS Credential Dumping + - 'Boot or Logon Autostart Execution: Security Support Provider' +DetectionPriority: CRITICAL +ThreatPrevalence: VERY HIGH +DetectionDifficulty: MEDIUM +Description: > + To extract plaintext credentials, NTLM hashes, or Kerberos tickets from a live + Windows system, an attacker must read the memory of the Local Security Authority + Subsystem Service (lsass.exe). Windows enforces process isolation at the kernel + level: any tool that reads another process's memory must first obtain a handle via + NtOpenProcess with appropriate access rights. This kernel-mediated handle request + is the chokepoint; it fires regardless of whether the attacker uses Mimikatz, + nanodump, comsvcs.dll, ProcDump, direct syscalls, or any future tool. Even + techniques that bypass userland API hooks (ntdll unhooking, direct syscalls) still + traverse the kernel's ObRegisterCallbacks path, which Sysmon Event ID 10 + (ProcessAccess) and ETW Threat Intelligence consume. The attacker cannot read + lsass memory without the kernel granting the handle. +LastUpdated: '2026-03-30' +Author: '@NovaSky0x1' + +Chokepoints: + - Stage: Handle Acquisition + Invariant: Any process must request a handle to lsass.exe with memory-read access rights from the Windows kernel. + WhyCantBypass: > + Windows enforces process isolation at the kernel level: NtOpenProcess must be + called to obtain a handle, and the kernel's ObRegisterCallbacks fires for every + handle request regardless of whether the caller used standard APIs or direct + syscalls. + LogSources: + - Sysmon Event ID 10 (ProcessAccess) + - Windows Security Event ID 4656 (Handle Requested) + - ETW Microsoft-Windows-Threat-Intelligence (kernel-level telemetry) + DetectionTier: Research + SigmaRef: sigma-rules/lsass-credential-dumping/research.yml + - Stage: Memory Read + Invariant: The process must read lsass.exe virtual memory to extract credential material using NtReadVirtualMemory or MiniDumpWriteDump. + WhyCantBypass: > + Credential material (NTLM hashes, Kerberos tickets, plaintext passwords cached + by WDigest/SSP) resides in lsass.exe process memory. There is no file or + registry location that contains the same live credential state. + LogSources: + - 'Sysmon Event ID 10 (ProcessAccess: CallTrace field reveals read mechanism)' + - 'Sysmon Event ID 11 (File Create: dump file written to disk)' + DetectionTier: Hunt + SigmaRef: sigma-rules/lsass-credential-dumping/hunt.yml + BypassNote: > + Handle duplication (NtDuplicateObject) allows an attacker to clone an existing + handle to lsass from another process, producing GrantedAccess 0x0040 instead of + the standard read masks. The hunt rule includes this pattern. + - Stage: Credential Extraction + Invariant: The attacker must parse LSASS memory structures or dump file contents to extract usable credentials, producing observable artifacts (either an in-memory read with a suspicious CallTrace, a dump file on disk, or a DLL injected into lsass via SSP). + WhyCantBypass: > + Credential structures in lsass memory use Microsoft's internal SSP format. + The attacker must either parse them in-process (generating the ProcessAccess + event) or write a dump file for offline parsing (generating a FileCreate event). + SSP injection (loading a malicious DLL into lsass) generates an ImageLoaded + event for a DLL outside System32. + LogSources: + - 'Sysmon Event ID 10 (ProcessAccess: GrantedAccess + CallTrace correlation)' + - 'Sysmon Event ID 7 (Image Loaded: SSP DLL injection into lsass)' + - 'Sysmon Event ID 11 (File Create: dump file artifact)' + - 'Sysmon Event ID 1 (Process Creation: LOLBin execution)' + DetectionTier: Analyst + SigmaRef: sigma-rules/lsass-credential-dumping/analyst.yml + +Variations: + - Name: Mimikatz (sekurlsa::logonpasswords) + FirstSeen: 2011-Q2 + Status: Active + SourceURL: https://github.com/gentilkiwi/mimikatz + Notes: > + The original and most widely documented LSASS credential dumping tool. Opens + lsass.exe with PROCESS_ALL_ACCESS (0x1FFFFF) or PROCESS_VM_READ (0x1010). + Used by virtually every ransomware group and APT. GrantedAccess 0x1010 is the + classic Mimikatz fingerprint. + VariantId: mimikatz-sekurlsa + - Name: comsvcs.dll MiniDump (LOLBin) + FirstSeen: 2019-Q1 + Status: Active + SourceURL: https://lolbas-project.github.io/#/OtherMSBinaries/Comsvcs + Notes: > + Living-off-the-land technique using rundll32.exe to call the MiniDump export + from comsvcs.dll (a legitimate Windows DLL). Writes a full process dump of + lsass.exe to disk. Command pattern: rundll32.exe comsvcs.dll MiniDump + full. The MiniDump export name is a fixed Windows API; it cannot + be renamed without recompiling the DLL. + VariantId: comsvcs-minidump-lolbin + - Name: ProcDump (Sysinternals) + FirstSeen: 2016-Q1 + Status: Active + SourceURL: https://learn.microsoft.com/en-us/sysinternals/downloads/procdump + Notes: > + Microsoft Sysinternals tool used legitimately for debugging, repurposed for + LSASS dumping. Uses MiniDumpWriteDump API (dbgcore.dll/dbghelp.dll in CallTrace). + Signed by Microsoft, so it bypasses many application whitelisting policies. + VariantId: procdump-sysinternals + - Name: Nanodump + FirstSeen: 2022-Q1 + Status: Active + SourceURL: https://github.com/fortra/nanodump + Notes: > + Minimal LSASS dumper designed to evade detection. Uses direct syscalls, handle + duplication, and process forking techniques. GrantedAccess patterns vary: 0x0810 + for direct read, 0x0040 for handle duplication mode. Produces UNKNOWN in Sysmon + CallTrace when using direct syscalls. + VariantId: nanodump + - Name: HandleKatz + FirstSeen: 2021-Q3 + Status: Active + SourceURL: https://github.com/codewhitesec/HandleKatz + Notes: > + Abuses handle duplication to obtain a cloned handle to lsass.exe from another + process that already holds one. GrantedAccess 0x0040 (PROCESS_DUP_HANDLE). + Designed to evade detections that only look for direct PROCESS_VM_READ handles. + VariantId: handlekatz-dup + - Name: PPLBlade / PPLdump + FirstSeen: 2022-Q3 + Status: Active + SourceURL: https://github.com/tastypepperoni/PPLBlade + Notes: > + Bypasses Protected Process Light (PPL) protection on lsass.exe by exploiting + vulnerable signed drivers or ELAM driver abuse. Once PPL is defeated, standard + dump tools work. Detection shifts to the BYOVD/driver load stage (covered by + edr-bypass-techniques) plus the subsequent LSASS access event. + VariantId: pplblade-ppldump + - Name: Task Manager Manual Dump + FirstSeen: 2014-Q1 + Status: Active + Notes: > + Built-in Windows capability: right-click lsass.exe in Task Manager and select + "Create dump file." Writes a full memory dump to %TEMP%. Uses 0x1FFFFF + GrantedAccess from taskmgr.exe. Often used by less sophisticated attackers + or during hands-on-keyboard intrusions. + VariantId: task-manager-manual-dump + - Name: SSP Injection (mimilib / memssp) + FirstSeen: 2015-Q1 + Status: Active + SourceURL: https://attack.mitre.org/techniques/T1547/005/ + Notes: > + Injects a malicious Security Support Provider DLL into lsass.exe via + AddSecurityPackage API or direct registry manipulation (HKLM\SYSTEM\CCS\Control\Lsa\Security Packages). + The DLL logs all future authentication events to a file. Sysmon EID 7 + detects the DLL load from a non-System32 path. + VariantId: ssp-injection-mimilib + - Name: Direct Syscall Dumpers (SilentProcessExit, MirrorDump, SafetyKatz) + FirstSeen: 2020-Q2 + Status: Active + SourceURL: https://github.com/GhostPack/SafetyKatz + Notes: > + Family of tools that use direct system calls (syscall stubs) to bypass ntdll.dll + userland hooks placed by EDR products. The kernel callback (ObRegisterCallbacks) + still fires, so Sysmon EID 10 still generates, but the CallTrace shows UNKNOWN + instead of ntdll.dll. MirrorDump uses DLL injection into a process with an + existing LSASS handle. + VariantId: direct-syscall-dumpers + - Name: Pypykatz (Python) + FirstSeen: 2019-Q3 + Status: Active + SourceURL: https://github.com/skelsec/pypykatz + Notes: > + Pure Python implementation of Mimikatz credential extraction. Can parse LSASS + memory dumps offline or access live LSASS via ctypes. Cross-platform, works on + Linux for parsing dump files obtained from Windows. Overlaps with BYOSI chokepoint + when Python interpreter is brought onto the target. + VariantId: pypykatz-python + - Name: Impacket secretsdump.py (Remote) + FirstSeen: 2016-Q1 + Status: Active + SourceURL: https://github.com/fortra/impacket + Notes: > + Remote credential extraction over SMB. Supports multiple modes: DCSync + (replicating credentials via DRSUAPI), remote registry SAM/LSA dump, and + remote LSASS memory read via svcctl service creation. When using the LSASS + read mode, the service runs on the target and dumps locally. Overlaps with + the remote-execution-tools chokepoint for the SMB lateral movement stage. + VariantId: impacket-secretsdump + - Name: CrackMapExec / NetExec (--lsa, --sam) + FirstSeen: 2019-Q2 + Status: Active + SourceURL: https://github.com/Pennyw0rth/NetExec + Notes: > + Network-based credential harvesting across multiple hosts. The --lsa and + --sam flags dump credentials remotely via SMB service creation. The LSASS + access event occurs on the target host, not the attacker's machine. Used + heavily in ransomware operations for credential spraying across domains. + VariantId: crackmapexec-netexec + - Name: Cobalt Strike (logonpasswords, hashdump) + FirstSeen: 2014-Q1 + Status: Active + Notes: > + Built-in beacon commands for credential theft. logonpasswords injects + Mimikatz reflectively into memory; hashdump reads the SAM hive. Both + generate Sysmon EID 10 for the LSASS access. The source process is the + beacon's host process (often rundll32.exe or a sacrificial process), + producing a non-standard source path in most deployments. + VariantId: cobalt-strike-logonpasswords + - Name: Sliver (creds, sharp-dump) + FirstSeen: 2020-Q1 + Status: Active + SourceURL: https://github.com/BishopFox/sliver + Notes: > + Open-source C2 framework from BishopFox. Supports credential dumping via + execute-assembly (loading SharpDump or SharpKatz in-process) and through + built-in BOF (Beacon Object File) execution. The LSASS access originates + from the Sliver implant process, which typically runs from a user-writable + path or injected into a legitimate process. + VariantId: sliver-creds + - Name: Havoc (mimikatz, coffloader) + FirstSeen: 2022-Q3 + Status: Active + SourceURL: https://github.com/HavocFramework/Havoc + Notes: > + Open-source C2 framework with built-in Mimikatz integration and COFFLoader + for executing credential dumping BOFs. The LSASS access event comes from + the Havoc demon process. Gaining popularity as a Cobalt Strike alternative + in both red team and threat actor operations. + VariantId: havoc-mimikatz + - Name: Brute Ratel C4 (brc4, credstore) + FirstSeen: 2022-Q1 + Status: Active + Notes: > + Commercial adversary simulation tool that has been adopted by ransomware + operators (notably BlackCat/ALPHV). Includes built-in credential harvesting + capabilities. Uses syscall-level evasion techniques similar to nanodump, + producing UNKNOWN in Sysmon CallTrace. Leaked versions circulate in + criminal forums. + VariantId: brute-ratel-credstore + - Name: Mythic (Athena, Apollo agents) + FirstSeen: 2020-Q2 + Status: Active + SourceURL: https://github.com/its-a-feature/Mythic + Notes: > + Open-source C2 platform with modular agent architecture. Credential + dumping is implemented through agent-specific modules (Athena, Apollo) + that call MiniDumpWriteDump or use direct syscalls. The source process + varies by agent configuration and injection method. + VariantId: mythic-agents + - Name: Dumpert + FirstSeen: 2019-Q3 + Status: Active + SourceURL: https://github.com/outflanknl/Dumpert + Notes: > + One of the first public tools to use direct system calls for LSASS dumping, + bypassing ntdll.dll API hooks. Calls NtOpenProcess and NtCreateFile via + syscall stubs. Produces UNKNOWN in Sysmon CallTrace. Foundational technique + adopted by nanodump and subsequent evasion tools. + VariantId: dumpert-direct-syscall + - Name: SharpKatz / SharpDump (.NET) + FirstSeen: 2019-Q1 + Status: Active + SourceURL: https://github.com/GhostPack/SharpDump + Notes: > + C# implementations of credential dumping designed for execute-assembly + workflows in Cobalt Strike, Sliver, and similar frameworks. SharpKatz + reimplements Mimikatz in .NET; SharpDump creates a minidump of LSASS. + Both use MiniDumpWriteDump (dbgcore.dll in CallTrace) and run from + the beacon's process context. + VariantId: sharpkatz-sharpdump-dotnet + - Name: Out-Minidump (PowerShell) + FirstSeen: 2016-Q3 + Status: Declining + SourceURL: https://github.com/PowerShellMafia/PowerSploit + Notes: > + PowerShell-based LSASS dump using .NET P/Invoke to call MiniDumpWriteDump. + Part of the PowerSploit toolkit. Generates both a PowerShell script block + log and Sysmon EID 10. Less common now due to AMSI and Script Block Logging + making PowerShell-based attacks more visible. + VariantId: out-minidump-powershell + - Name: LSASS Shtinkering (Process Snapshotting) + FirstSeen: 2022-Q1 + Status: Emerging + SourceURL: https://github.com/deepinstinct/Lsass-Shtinkering + Notes: > + Uses PssNtCaptureSnapshot to create a snapshot of the LSASS process, then + reads credentials from the snapshot instead of live memory. The snapshot + API still requires a handle to lsass.exe, so Sysmon EID 10 fires, but + the GrantedAccess mask may differ from standard dump patterns. Some EDR + products do not monitor snapshot operations. + VariantId: lsass-shtinkering-snapshot + - Name: Skeleton Key (SSP Backdoor) + FirstSeen: 2015-Q1 + Status: Active + SourceURL: https://attack.mitre.org/software/S0007/ + Notes: > + Variant of SSP injection that patches the LSASS authentication flow to + accept a universal "skeleton key" password for any domain account. Unlike + mimilib which logs credentials, Skeleton Key modifies authentication + in-memory. Detected via Sysmon EID 7 (DLL loaded into lsass from + non-System32 path) and anomalous Kerberos authentication patterns. + VariantId: skeleton-key-ssp + - Name: LaZagne + FirstSeen: 2015-Q1 + Status: Active + SourceURL: https://github.com/AlessandroZ/LaZagne + Notes: > + Multi-platform credential harvester that extracts passwords from browsers, + databases, mail clients, Wi-Fi, and LSASS. Uses ctypes on Windows to call + OpenProcess against lsass.exe. Cross-platform (Python), often deployed + alongside BYOSI techniques. + VariantId: lazagne-multi-platform + - Name: EDRSandBlast (LSASS dump mode) + FirstSeen: 2022-Q4 + Status: Active + SourceURL: https://github.com/wavestone-cdt/EDRSandblast + Notes: > + Combines BYOVD driver exploitation with LSASS credential dumping in a + single tool. Loads a vulnerable driver to blind EDR kernel callbacks, then + dumps LSASS. The driver load is detectable via Sysmon EID 6 (see + edr-bypass-techniques); the LSASS access still generates EID 10 if Sysmon + kernel callbacks survive the patching attempt. + VariantId: edrsandblast-lsass + +Prerequisites: + - The attacker must have local administrator or SYSTEM privileges on the target host (LSASS access requires SeDebugPrivilege or equivalent) + - LSASS must not be running as a Protected Process Light (PPL), or the attacker must first bypass PPL (see edr-bypass-techniques) + - Credential Guard (VBS) must not be active, or the attacker must compromise the isolated LSA environment (significantly harder, no known public tools) + - Sysmon or equivalent kernel-level telemetry must be deployed for chokepoint visibility (Security EID 4656 provides partial coverage without Sysmon) + +EvolutionTimeline: + - Date: 2011-Q2 + Event: Mimikatz released by Benjamin Delpy + Change: > + First publicly available tool for extracting plaintext credentials from LSASS + memory. Used PROCESS_ALL_ACCESS (0x1FFFFF) handle with standard Windows API + calls through ntdll.dll. + DetectionImpact: > + No detection existed. LSASS memory access was not monitored by any standard + Windows audit configuration. Security products relied on signature-based + detection of the Mimikatz binary itself. + TheConstant: A process must open a handle to lsass.exe and read its virtual memory + Variants: [] + EventType: event + - Date: 2016-Q1 + Event: 'LOLBin techniques emerge: ProcDump and comsvcs.dll repurposed for LSASS dumping' + Change: > + Attackers shifted from custom tools to Microsoft-signed binaries (procdump.exe, + rundll32.exe + comsvcs.dll) to bypass application whitelisting and signature + detection. The dump is written to disk for offline parsing. + DetectionImpact: > + Binary signature detection bypassed completely. Detection shifted to process + creation monitoring for known LOLBin command patterns and file creation events + for .dmp files in temp directories. + TheConstant: A process must open a handle to lsass.exe and read its virtual memory + Variants: [] + EventType: event + - Date: 2019-Q2 + Event: Sysmon EID 10 (ProcessAccess) adopted as primary LSASS monitoring source + Change: > + Microsoft Sysinternals added ProcessAccess logging to Sysmon, providing + kernel-level visibility into handle requests targeting lsass.exe. The + GrantedAccess and CallTrace fields became the foundation for behavioral + LSASS access detection independent of specific tool signatures. + DetectionImpact: > + Transformed LSASS monitoring from signature-based to behavior-based. Defenders + could now detect any tool accessing LSASS by its access mask and calling + mechanism rather than its binary name or hash. + TheConstant: A process must open a handle to lsass.exe and read its virtual memory + Variants: [] + EventType: event + - Date: 2020-Q2 + Event: Direct syscall and ntdll unhooking techniques proliferate + Change: > + Tools like SilentProcessExit, MirrorDump, and custom loaders bypass EDR + userland hooks by making system calls directly to the kernel, skipping + ntdll.dll entirely. This produces UNKNOWN in Sysmon CallTrace instead of + the standard ntdll.dll entry. + DetectionImpact: > + EDR products relying on ntdll.dll API hooks lost visibility. Sysmon EID 10 + still fires because the kernel ObRegisterCallbacks mechanism operates below + the userland hook layer. UNKNOWN in CallTrace became a detection signal + rather than a blind spot. + TheConstant: A process must open a handle to lsass.exe and read its virtual memory + Variants: [] + EventType: event + - Date: 2021-Q3 + Event: Handle duplication evasion (HandleKatz, nanodump duphandle mode) + Change: > + Instead of directly opening lsass.exe, these tools open a different process + that already holds a handle to lsass, then duplicate that handle via + NtDuplicateObject. This produces GrantedAccess 0x0040 (PROCESS_DUP_HANDLE) + rather than the expected 0x1010 or 0x1FFFFF. + DetectionImpact: > + Detection rules looking only for PROCESS_VM_READ or PROCESS_ALL_ACCESS missed + the duplication pattern. Rules updated to include 0x0040 as a suspicious + GrantedAccess value when targeting lsass.exe from a non-standard source path. + TheConstant: A process must open a handle to lsass.exe and read its virtual memory + Variants: [] + EventType: event + - Date: 2022-Q3 + Event: PPL bypass tools combine BYOVD with LSASS dumping + Change: > + PPLBlade, PPLdump, and similar tools load a vulnerable signed kernel driver + to disable Protected Process Light on lsass.exe before performing the dump. + Two-stage attack: driver load (EID 6) precedes LSASS access (EID 10). + DetectionImpact: > + PPL protection is defeated before the dump occurs, so the LSASS access event + appears normal from an access-rights perspective. Detection requires + correlating the vulnerable driver load with subsequent LSASS access. See + edr-bypass-techniques for the driver load stage. + TheConstant: A process must open a handle to lsass.exe and read its virtual memory + Variants: [] + EventType: event + - Date: 2024-Q3 + Event: LSASS credential dumping remains universal across ransomware groups + Change: > + Kaspersky, Mandiant, and Cisco Talos reports confirm T1003.001 in 5 of 5 + major ransomware families (BlackBasta, BlackCat, Akira, Qilin, LockBit). + Tool choice varies (Mimikatz, comsvcs.dll, nanodump, custom tools) but + the LSASS access event is present in every case. + DetectionImpact: > + No new evasion of the kernel-level chokepoint. Tool diversity increased but + behavioral detection via Sysmon EID 10 remained effective across all variants. + TheConstant: A process must open a handle to lsass.exe and read its virtual memory + Variants: [] + EventType: event + +EmulationScript: + File: emulation/lsass-credential-dumping/emulate.ps1 + Language: powershell + AtomicRef: T1003.001 + Description: Simulates LSASS credential dumping chokepoint stages for detection validation + SafetyNotes: > + Run in an isolated lab VM with Sysmon deployed. Requires Administrator privileges. + Does NOT extract credentials. Opens and immediately closes a handle to lsass.exe + to generate EID 10 telemetry, simulates comsvcs.dll command line for EID 1, and + creates a marker .dmp file for EID 11. + +Detections: + - Level: Research + Description: Baseline all non-system processes accessing lsass.exe with memory-read permissions + LogSources: + - Sysmon Event ID 10 (ProcessAccess) + Logic: > + Monitor ProcessAccess events where TargetImage is lsass.exe and GrantedAccess + includes memory-read flags (0x1010, 0x1FFFFF, 0x1410, 0x0810, 0x0040, 0x1038, + 0x1438, 0x0010). Filter only core OS processes (csrss.exe, services.exe, + svchost.exe, lsass.exe self-access, lsaiso.exe, wininit.exe, smss.exe, + winlogon.exe). Everything else, including AV/EDR products, WerFault, + and Task Manager, appears in this baseline. Run for one week to establish the + environment-specific set of legitimate LSASS accessors before tuning. + ExpectedFPRate: High + UseCase: > + Detection engineers baselining LSASS access patterns in a new environment. + Identifies which processes normally touch LSASS to build the environment-specific + allowlist needed for Hunt and Analyst rules. + SigmaRule: sigma-rules/lsass-credential-dumping/research.yml + + - Level: Hunt + Description: LSASS access with suspicious CallTrace, non-standard source path, or LOLBin dump pattern + LogSources: + - Sysmon Event ID 10 (ProcessAccess) + - Sysmon Event ID 1 (Process Creation) + Logic: > + ProcessAccess to lsass.exe with credential-dump access masks WHERE (A) CallTrace + contains dbgcore.dll or dbghelp.dll (MiniDumpWriteDump, used by comsvcs.dll, + ProcDump, Out-Minidump) or UNKNOWN (direct syscall / ntdll unhooking), OR (B) + SourceImage is in a user-writable path (Temp, Downloads, AppData, ProgramData, + Users\Public), OR (C) Process creation matches LOLBin patterns (rundll32 + + comsvcs + MiniDump, or procdump targeting lsass). Excludes core OS processes, + known AV/EDR paths (Program Files\Windows Defender, CrowdStrike, SentinelOne, + Sophos, etc.), and WerFault. + ExpectedFPRate: Medium + UseCase: > + Active threat hunting for credential dumping. Periodic sweeps during incident + response or campaign investigations. CallTrace analysis separates legitimate + security product access from dump tooling behavior. + SigmaRule: sigma-rules/lsass-credential-dumping/hunt.yml + + - Level: Analyst + Description: Non-standard process accessing LSASS with dump mechanism fingerprint and credential-dump access rights + LogSources: + - Sysmon Event ID 10 (ProcessAccess) + Logic: > + ProcessAccess to lsass.exe with credential-dump access mask (0x1FFFFF, + 0x1010, 0x1410, 0x0810, 0x1038, 0x1438) AND CallTrace shows + MiniDumpWriteDump (dbgcore.dll, dbghelp.dll) or direct syscall (UNKNOWN) + AND source process is outside System32 and Program Files. This triple-AND + eliminates virtually all legitimate LSASS access; AV/EDR runs from Program + Files with clean CallTraces. A secondary selection covers handle duplication + (GrantedAccess 0x0040) targeting lsass from non-standard paths, catching the + HandleKatz and nanodump duphandle evasion technique. Supplementary detections + for comsvcs.dll MiniDump LOLBin (process_creation), SSP injection + (image_load), and dump file artifacts (file_event) should be deployed as + companion SIEM rules for additional coverage across event types. + ExpectedFPRate: Low + UseCase: > + Automated SOC alerting. Direct escalation to Tier 2/IR. If this fires, + assume credential compromise and begin containment (isolate host, reset + exposed credentials, check for lateral movement via pass-the-hash). + SigmaRule: sigma-rules/lsass-credential-dumping/analyst.yml + +Intel: + - Name: 'MITRE ATT&CK: T1003.001, OS Credential Dumping: LSASS Memory' + Tier: primary + URL: https://attack.mitre.org/techniques/T1003/001/ + Description: > + Primary technique definition. Documents real-world procedures by Mimikatz, + ProcDump, Windows Task Manager, and comsvcs.dll. Lists mitigations including + Credential Guard and PPL. + - Name: 'Microsoft: Credential Guard Overview' + Tier: supporting + URL: https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/ + Description: > + Microsoft's documentation on Credential Guard (Virtualization Based Security). + When deployed, isolates LSASS credential material into a separate virtual + machine, preventing direct memory read attacks entirely. The chokepoint + detection remains relevant for environments without Credential Guard. + - Name: 'Sysmon: Event ID 10 ProcessAccess' + Tier: supporting + URL: https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon + Description: > + Sysmon documentation covering ProcessAccess event generation. Critical for + understanding GrantedAccess masks, CallTrace format, and configuration + requirements for LSASS monitoring. + - Name: 'Fortra: Nanodump' + Tier: supporting + URL: https://github.com/fortra/nanodump + Description: > + Source code for nanodump, a minimal LSASS dumper demonstrating direct syscall, + handle duplication, and process forking evasion techniques. Essential reference + for understanding modern credential dump evasion and why GrantedAccess 0x0040 + and UNKNOWN CallTrace patterns must be included in detection rules. + +RelatedChokepoints: + - browser-credential-theft + - edr-bypass-techniques + - remote-execution-tools + +OsintSources: + - Platform: VirusTotal Intelligence + Query: 'behavior_processes:"lsass" behavior:"NtOpenProcess" tag:cred-stealer' + Notes: > + Finds malware samples that access lsass.exe during sandbox execution. Pivot + to the behavior tab to extract GrantedAccess patterns and dump methodology + used by each sample. Cross-reference with CallTrace values to identify + new evasion techniques. + - Platform: VirusTotal Intelligence + Query: 'content:"sekurlsa" OR content:"MiniDumpWriteDump" OR content:"comsvcs" positives:5+' + Notes: > + Finds samples containing known credential dump strings. Useful for tracking + new Mimikatz variants, custom dump tools, and LOLBin abuse scripts that + reference comsvcs.dll MiniDump. + - Platform: GitHub Code Search + Query: '"NtOpenProcess" "lsass" language:C OR language:C++' + Notes: > + Finds new credential dumping tool source code. Monitor for novel evasion + techniques: direct syscall wrappers, handle duplication implementations, + and process forking methods that may require detection rule updates. + - Platform: GitHub Code Search + Query: '"MiniDumpWriteDump" "lsass" OR "sekurlsa" language:C#' + Notes: > + Finds .NET-based credential dump tools (SharpKatz, SafetyKatz, SharpDump). + These generate dbgcore.dll in CallTrace, confirming analyst rule coverage. + - Platform: LOLDrivers + Query: https://www.loldrivers.io/ + Notes: > + Database of known vulnerable kernel drivers used for BYOVD attacks. PPL + bypass tools (PPLBlade, PPLdump) require loading a vulnerable driver before + dumping LSASS. Cross-reference with edr-bypass-techniques chokepoint for + driver load detection coverage. + - Platform: ANY.RUN + Query: 'suricata:"lsass" OR commandline:"sekurlsa" OR commandline:"comsvcs"' + Notes: > + Sandbox search for samples that interact with lsass.exe during execution. + ANY.RUN provides process tree visualization showing the parent-child chain + and GrantedAccess values, useful for building detection rule context. + +References: + - https://attack.mitre.org/techniques/T1003/001/ + - https://attack.mitre.org/techniques/T1003/ + - https://github.com/fortra/nanodump + - https://github.com/codewhitesec/HandleKatz + - https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/ + - https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon + - https://www.blackhillsinfosec.com/red-teamers-cookbook-byoi-bring-your-own-interpreter/ + +RawLogs: + - Source: Microsoft-Windows-Sysmon/Operational + EventId: 10 + Description: 'Mimikatz-style LSASS handle acquisition: classic 0x1010 access mask from user-writable path' + MatchedRules: + - Research + - Hunt + - Analyst + Sample: > + EventID: 10 (ProcessAccess) + UtcTime: 2025-11-14 02:31:18.442 + SourceProcessGUID: {a1b2c3d4-5e6f-7890-abcd-ef0123456789} + SourceProcessId: 7284 + SourceImage: C:\Users\jsmith\AppData\Local\Temp\procdump64.exe + TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004} + TargetProcessId: 672 + TargetImage: C:\Windows\System32\lsass.exe + GrantedAccess: 0x1010 + CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\Windows\SYSTEM32\dbgcore.dll+6350|C:\Users\jsmith\AppData\Local\Temp\procdump64.exe+1f234 + - Source: Microsoft-Windows-Sysmon/Operational + EventId: 10 + Description: 'Direct syscall LSASS access: UNKNOWN in CallTrace indicates ntdll hook bypass' + MatchedRules: + - Research + - Hunt + - Analyst + Sample: > + EventID: 10 (ProcessAccess) + UtcTime: 2025-11-14 02:44:07.891 + SourceProcessGUID: {a1b2c3d4-9a8b-7c6d-5e4f-3a2b1c0d9e8f} + SourceProcessId: 3412 + SourceImage: C:\Users\jsmith\Downloads\update.exe + TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004} + TargetProcessId: 672 + TargetImage: C:\Windows\System32\lsass.exe + GrantedAccess: 0x1FFFFF + CallTrace: UNKNOWN + - Source: Microsoft-Windows-Sysmon/Operational + EventId: 10 + Description: 'Handle duplication targeting LSASS: HandleKatz/nanodump evasion with GrantedAccess 0x0040' + MatchedRules: + - Analyst + Sample: > + EventID: 10 (ProcessAccess) + UtcTime: 2025-11-14 03:02:55.103 + SourceProcessGUID: {a1b2c3d4-1122-3344-5566-778899aabbcc} + SourceProcessId: 5890 + SourceImage: C:\ProgramData\staging\svcloader.exe + TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004} + TargetProcessId: 672 + TargetImage: C:\Windows\System32\lsass.exe + GrantedAccess: 0x0040 + CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\ProgramData\staging\svcloader.exe+a238 + - Source: Microsoft-Windows-Sysmon/Operational + EventId: 1 + Description: 'comsvcs.dll MiniDump LOLBin: rundll32 invoking MiniDump export for LSASS dump' + MatchedRules: + - Hunt + Sample: > + EventID: 1 (Process Create) + UtcTime: 2025-11-14 03:15:22.667 + ProcessGUID: {a1b2c3d4-aabb-ccdd-eeff-001122334455} + ProcessId: 8844 + Image: C:\Windows\System32\rundll32.exe + CommandLine: rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full + ParentProcessGUID: {a1b2c3d4-5566-7788-99aa-bbccddeeff00} + ParentProcessId: 4120 + ParentImage: C:\Windows\System32\cmd.exe + ParentCommandLine: cmd.exe /c rundll32.exe comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full + +TheConstant: A process must open a kernel-mediated handle to lsass.exe and read its virtual memory to extract credential material diff --git a/emulation/lsass-credential-dumping/emulate.ps1 b/emulation/lsass-credential-dumping/emulate.ps1 new file mode 100644 index 0000000..b9f57e2 --- /dev/null +++ b/emulation/lsass-credential-dumping/emulate.ps1 @@ -0,0 +1,240 @@ +#Requires -Version 5.1 +#Requires -RunAsAdministrator +# MITRE ATT&CK: T1003.001, OS Credential Dumping: LSASS Memory +# Simulates LSASS credential dumping chokepoint stages: handle acquisition, memory read, and dump artifact. +# Does NOT extract credentials; uses safe API calls to generate detection telemetry only. + +[CmdletBinding()] +param( + [switch]$SkipDumpFile, + [switch]$CleanupOnly, + [string]$DumpPath = (Join-Path $env:TEMP "lsass_emu_$(Get-Random).dmp") +) + +Set-StrictMode -Version Latest +$ErrorActionPreference = 'Continue' + +function Write-Step ([string]$Msg) { Write-Host "[*] $Msg" -ForegroundColor Cyan } +function Write-Ok ([string]$Msg) { Write-Host "[+] $Msg" -ForegroundColor Green } +function Write-Warn ([string]$Msg) { Write-Host "[!] $Msg" -ForegroundColor Yellow } + +function Remove-Artefacts { + if (Test-Path $DumpPath) { + Remove-Item -Path $DumpPath -Force -ErrorAction SilentlyContinue + Write-Ok "Removed dump artefact: $DumpPath" + } else { + Write-Warn "No artefacts found at $DumpPath" + } +} + +if ($CleanupOnly) { Remove-Artefacts; exit 0 } + +Write-Host "" +Write-Host "=== LSASS Credential Dumping Emulation ===" -ForegroundColor Magenta +Write-Host " T1003.001 | Detection Chokepoints Project" -ForegroundColor DarkGray +Write-Host "" +Write-Warn "This script generates detection telemetry ONLY." +Write-Warn "No credentials are extracted. No memory is parsed." +Write-Warn "Requires Administrator privileges for SeDebugPrivilege." +Write-Host "" + +# ─── Enable SeDebugPrivilege ──────────────────────────────────────────────── + +Write-Step "Enabling SeDebugPrivilege (required for LSASS handle access)" + +Add-Type -TypeDefinition @' +using System; +using System.Diagnostics; +using System.Runtime.InteropServices; + +public class LsassChokepointEmulation { + [DllImport("kernel32.dll", SetLastError = true)] + public static extern IntPtr OpenProcess( + uint dwDesiredAccess, bool bInheritHandle, int dwProcessId); + + [DllImport("kernel32.dll", SetLastError = true)] + [return: MarshalAs(UnmanagedType.Bool)] + public static extern bool CloseHandle(IntPtr hObject); + + [DllImport("advapi32.dll", SetLastError = true)] + [return: MarshalAs(UnmanagedType.Bool)] + public static extern bool OpenProcessToken( + IntPtr ProcessHandle, uint DesiredAccess, out IntPtr TokenHandle); + + [DllImport("advapi32.dll", SetLastError = true, CharSet = CharSet.Auto)] + [return: MarshalAs(UnmanagedType.Bool)] + public static extern bool LookupPrivilegeValue( + string lpSystemName, string lpName, out long lpLuid); + + [DllImport("advapi32.dll", SetLastError = true)] + [return: MarshalAs(UnmanagedType.Bool)] + public static extern bool AdjustTokenPrivileges( + IntPtr TokenHandle, bool DisableAllPrivileges, + ref TOKEN_PRIVILEGES NewState, int BufferLength, + IntPtr PreviousState, IntPtr ReturnLength); + + [DllImport("kernel32.dll")] + public static extern IntPtr GetCurrentProcess(); + + [StructLayout(LayoutKind.Sequential)] + public struct TOKEN_PRIVILEGES { + public int PrivilegeCount; + public long Luid; + public int Attributes; + } + + public const uint TOKEN_ADJUST_PRIVILEGES = 0x0020; + public const uint TOKEN_QUERY = 0x0008; + public const int SE_PRIVILEGE_ENABLED = 0x00000002; + public const uint PROCESS_VM_READ_QUERY = 0x1010; + + public static bool EnableDebugPrivilege() { + IntPtr tokenHandle; + if (!OpenProcessToken(GetCurrentProcess(), + TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, out tokenHandle)) + return false; + + long luid; + if (!LookupPrivilegeValue(null, "SeDebugPrivilege", out luid)) { + CloseHandle(tokenHandle); + return false; + } + + TOKEN_PRIVILEGES tp = new TOKEN_PRIVILEGES(); + tp.PrivilegeCount = 1; + tp.Luid = luid; + tp.Attributes = SE_PRIVILEGE_ENABLED; + + bool result = AdjustTokenPrivileges(tokenHandle, false, ref tp, 0, + IntPtr.Zero, IntPtr.Zero); + CloseHandle(tokenHandle); + return result && Marshal.GetLastWin32Error() == 0; + } + + public static int OpenLsass() { + Process[] procs = Process.GetProcessesByName("lsass"); + if (procs.Length == 0) return -1; + + int pid = procs[0].Id; + IntPtr handle = OpenProcess(PROCESS_VM_READ_QUERY, false, pid); + + if (handle == IntPtr.Zero) return -2; + + // Handle acquired. Sysmon EID 10 has fired. + // Close immediately; we do not read memory. + CloseHandle(handle); + return pid; + } +} +'@ + +$privEnabled = [LsassChokepointEmulation]::EnableDebugPrivilege() +if ($privEnabled) { + Write-Ok "SeDebugPrivilege enabled" +} else { + Write-Warn "Failed to enable SeDebugPrivilege. Handle acquisition may fail." + Write-Warn "This is expected if LSASS is running as PPL (Protected Process Light)." +} + +Start-Sleep -Milliseconds 300 + +# ─── Stage 1: Handle Acquisition (Sysmon EID 10, ProcessAccess) ───────────── + +Write-Step "Stage 1/3: Opening handle to lsass.exe (ProcessAccess telemetry)" +Write-Verbose " Targets: Sysmon EID 10 with TargetImage=lsass.exe" +Write-Verbose " This is the chokepoint invariant; every dump tool must do this" + +try { + $result = [LsassChokepointEmulation]::OpenLsass() + if ($result -gt 0) { + Write-Ok "Handle opened to lsass.exe (PID $result) with GrantedAccess 0x1010" + Write-Ok "Handle closed immediately, no memory read performed" + Write-Ok "Sysmon EID 10 generated: TargetImage=lsass.exe, GrantedAccess=0x1010" + } elseif ($result -eq -1) { + Write-Warn "lsass.exe process not found (are you running on Windows?)" + } else { + $err = [System.Runtime.InteropServices.Marshal]::GetLastWin32Error() + if ($err -eq 5) { + Write-Warn "OpenProcess returned ACCESS_DENIED (error 5)" + Write-Warn "LSASS is likely running as Protected Process Light (PPL)." + Write-Warn "PPL blocks handle acquisition even with SeDebugPrivilege." + Write-Warn "To test Stage 1, either:" + Write-Warn " 1. Disable PPL: reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL /t REG_DWORD /d 0 /f (reboot required)" + Write-Warn " 2. Use a VM without PPL enabled" + Write-Warn " 3. Accept that PPL is working as intended (this IS the defense)" + Write-Warn "" + Write-Warn "Sysmon may still log the failed access attempt as EID 10." + Write-Warn "Check for GrantedAccess=0x0 or a reduced mask in your logs." + } else { + Write-Warn "OpenProcess failed (error $err)" + } + } +} catch { + Write-Warn "Handle acquisition failed: $_" +} + +Start-Sleep -Milliseconds 500 + +# ─── Stage 2: comsvcs.dll MiniDump LOLBin (Sysmon EID 1, Process Creation) ── + +Write-Step "Stage 2/3: Simulating comsvcs.dll MiniDump command line (LOLBin telemetry)" +Write-Verbose " Generates Sysmon EID 1 with CommandLine containing 'comsvcs' and 'MiniDump'" +Write-Verbose " This is the most common LOLBin technique for LSASS dumping" + +# Echo the command line pattern without actually calling MiniDump +# This generates a process creation event with the suspicious command line +$lsassPid = (Get-Process lsass -ErrorAction SilentlyContinue).Id +if ($lsassPid) { + $cmdLine = "rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump $lsassPid $DumpPath full" + Write-Ok "LOLBin command pattern: $cmdLine" + # Run cmd /c echo with the suspicious command line to trigger EID 1 matching + cmd.exe /c "echo EMULATION_ONLY: $cmdLine" 2>&1 | Out-Null + Write-Ok "Sysmon EID 1 generated with comsvcs.dll MiniDump in CommandLine" +} else { + Write-Warn "lsass.exe PID not found, skipping LOLBin simulation" +} + +Start-Sleep -Milliseconds 500 + +# ─── Stage 3: Dump File Artifact (Sysmon EID 11, File Create) ─────────────── + +if (-not $SkipDumpFile) { + Write-Step "Stage 3/3: Creating dump file artefact in temp directory" + Write-Verbose " Creates a marker .dmp file to trigger file creation detection" + Write-Verbose " Targets: Sysmon EID 11 with TargetFilename=*.dmp in temp path" + + # Write a safe marker file (NOT a real memory dump) + $marker = "LSASS_EMULATION_MARKER | Detection Chokepoints Project | NOT A REAL DUMP" + [System.IO.File]::WriteAllText($DumpPath, $marker) + Write-Ok "Dump artefact created: $DumpPath" + Write-Ok "Sysmon EID 11 generated: .dmp file in temp directory" +} else { + Write-Warn "Stage 3 skipped (-SkipDumpFile flag set)" +} + +# ─── Summary ───────────────────────────────────────────────────────────────── + +Write-Host "" +Write-Step "Cleaning up artefacts" +Remove-Artefacts + +Write-Host "" +Write-Host "=== Emulation Complete ===" -ForegroundColor Magenta +Write-Host "" +Write-Host "Expected detections:" -ForegroundColor White +Write-Host " [Research] Sysmon EID 10: non-system process opened handle to lsass.exe" -ForegroundColor DarkCyan +Write-Host " [Hunt] EID 10: GrantedAccess 0x1010 + CallTrace from non-AV/EDR process" -ForegroundColor DarkYellow +Write-Host " [Analyst] EID 10: 0x1010 + CallTrace + non-standard source path" -ForegroundColor DarkGreen +Write-Host "" +Write-Host "Supplementary signals (deploy as companion SIEM rules):" -ForegroundColor DarkGray +Write-Host " EID 1: comsvcs.dll MiniDump command line pattern" +Write-Host " EID 11: .dmp file created in temp directory" +Write-Host "" +Write-Host "Cleanup:" -ForegroundColor DarkGray +Write-Host " .\emulate.ps1 -CleanupOnly" +Write-Host "" +Write-Host "For higher-fidelity testing (isolated lab VM only):" -ForegroundColor DarkGray +Write-Host " 1. rundll32.exe comsvcs.dll MiniDump C:\Temp\test.dmp full" +Write-Host " 2. procdump.exe -accepteula -ma lsass.exe C:\Temp\lsass.dmp" +Write-Host " 3. These generate authentic EID 10 with dbgcore.dll in CallTrace" +Write-Host "" diff --git a/sigma-rules/lsass-credential-dumping/analyst.yml b/sigma-rules/lsass-credential-dumping/analyst.yml new file mode 100644 index 0000000..8ebf310 --- /dev/null +++ b/sigma-rules/lsass-credential-dumping/analyst.yml @@ -0,0 +1,82 @@ +title: 'LSASS Credential Dump: Non-Standard Process with Dump Mechanism and Suspicious Access Rights' +id: 2abc46f9-9c70-47cf-932e-fe803e06f5c7 +status: experimental +description: > + High-fidelity detection for LSASS credential dumping. Detects a non-standard process + (outside System32 and Program Files) opening a handle to lsass.exe with credential-dump + access rights where the CallTrace reveals MiniDumpWriteDump usage (dbgcore.dll, + dbghelp.dll) or direct syscall evasion (UNKNOWN). This triple-AND (suspicious access + mask, dump mechanism fingerprint, and non-standard source path) eliminates virtually + all legitimate LSASS access. AV/EDR products run from Program Files with clean + CallTraces; attack tools run from temp paths with dbgcore.dll or UNKNOWN stacks. + A secondary selection covers handle duplication (GrantedAccess 0x0040) from non-standard + paths, the HandleKatz and nanodump evasion technique that uses NtDuplicateObject to + clone an existing LSASS handle instead of requesting a direct read handle. This + GrantedAccess value targeting lsass.exe from outside System32/Program Files has no + legitimate use case. Supplementary detections for comsvcs.dll MiniDump LOLBin + (process_creation), SSP injection (image_load), and dump file artifacts (file_event) + should be implemented as companion rules at the SIEM level for coverage across event + types. If this rule fires, assume credential compromise and begin host isolation. +references: + - https://attack.mitre.org/techniques/T1003/001/ + - https://github.com/fortra/nanodump + - https://github.com/codewhitesec/HandleKatz + - https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon + - https://www.microsoft.com/en-us/security/blog/2022/10/05/detecting-and-preventing-lsass-credential-dumping-attacks/ + - https://unit42.paloaltonetworks.com/mimikatz-overview/ +author: "@NovaSky0x1" +date: 2026/03/30 +tags: + - attack.credential_access + - attack.t1003.001 + - attack.t1003 + - detection.maturity.analyst +logsource: + category: process_access + product: windows +detection: + selection_lsass_target: + TargetImage|endswith: '\lsass.exe' + GrantedAccess|contains: + - '0x1FFFFF' + - '0x1010' + - '0x1410' + - '0x0810' + - '0x1038' + - '0x1438' + selection_dump_mechanism: + CallTrace|contains: + - 'dbgcore.dll' + - 'dbghelp.dll' + - 'UNKNOWN' + selection_nonstandard_source: + SourceImage|not|startswith: + - 'C:\Windows\System32\' + - 'C:\Windows\SysWOW64\' + - 'C:\Program Files\' + - 'C:\Program Files (x86)\' + selection_handle_duplication: + TargetImage|endswith: '\lsass.exe' + GrantedAccess: '0x0040' + SourceImage|not|startswith: + - 'C:\Windows\System32\' + - 'C:\Windows\SysWOW64\' + - 'C:\Program Files\' + - 'C:\Program Files (x86)\' + filter_os_core: + SourceImage|startswith: + - 'C:\Windows\System32\csrss.exe' + - 'C:\Windows\System32\lsass.exe' + - 'C:\Windows\System32\services.exe' + - 'C:\Windows\System32\svchost.exe' + - 'C:\Windows\System32\wininit.exe' + - 'C:\Windows\System32\lsaiso.exe' + - 'C:\Windows\System32\smss.exe' + - 'C:\Windows\System32\winlogon.exe' + condition: > + (selection_lsass_target and selection_dump_mechanism and selection_nonstandard_source and not filter_os_core) + or selection_handle_duplication +falsepositives: + - Portable diagnostic tools run by administrators from non-standard paths that access LSASS (should be blocked by policy in hardened environments) + - Authorized red team or penetration testing tools during sanctioned engagements +level: high diff --git a/sigma-rules/lsass-credential-dumping/hunt.yml b/sigma-rules/lsass-credential-dumping/hunt.yml new file mode 100644 index 0000000..2a17e44 --- /dev/null +++ b/sigma-rules/lsass-credential-dumping/hunt.yml @@ -0,0 +1,94 @@ +title: LSASS Access with Suspicious CallTrace or Non-Standard Source Path +id: 3d932b09-9d74-428d-bb0f-9368b28c6bb9 +status: experimental +description: > + Hunt-level detection for LSASS credential dumping. Adds behavioral context to the + research baseline to separate attack tooling from legitimate security products. + CallTrace analysis reveals the mechanism used to read LSASS memory: dbgcore.dll + and dbghelp.dll indicate MiniDumpWriteDump (ProcDump, comsvcs.dll, custom dump + tools), while UNKNOWN indicates direct syscalls or ntdll unhooking. Legitimate + AV/EDR products produce clean API call stacks without these indicators. Source + path filtering captures tools staged in user-writable directories; attack tools + land in Temp, Downloads, AppData while legitimate security products run from + Program Files. This rule excludes known AV/EDR paths and WerFault to reduce the + research baseline to actionable hunt leads. +references: + - https://attack.mitre.org/techniques/T1003/001/ + - https://github.com/fortra/nanodump + - https://github.com/codewhitesec/HandleKatz + - https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon + - https://www.microsoft.com/en-us/security/blog/2022/10/05/detecting-and-preventing-lsass-credential-dumping-attacks/ +author: "@NovaSky0x1" +date: 2026/03/30 +tags: + - attack.credential_access + - attack.t1003.001 + - attack.t1003 + - detection.maturity.hunt +logsource: + category: process_access + product: windows +detection: + selection_lsass_access: + TargetImage|endswith: '\lsass.exe' + GrantedAccess|contains: + - '0x1FFFFF' + - '0x1010' + - '0x1410' + - '0x0810' + - '0x1038' + - '0x1438' + - '0x0040' + selection_suspicious_calltrace: + CallTrace|contains: + - 'dbgcore.dll' + - 'dbghelp.dll' + - 'UNKNOWN' + selection_suspicious_source_path: + SourceImage|contains: + - '\Temp\' + - '\tmp\' + - '\Downloads\' + - '\AppData\' + - '\Users\Public\' + - '\ProgramData\' + - '\Desktop\' + - '\Recycle' + filter_os_core: + SourceImage|startswith: + - 'C:\Windows\System32\csrss.exe' + - 'C:\Windows\System32\lsass.exe' + - 'C:\Windows\System32\services.exe' + - 'C:\Windows\System32\svchost.exe' + - 'C:\Windows\System32\wininit.exe' + - 'C:\Windows\System32\lsaiso.exe' + - 'C:\Windows\System32\smss.exe' + - 'C:\Windows\System32\winlogon.exe' + filter_security_products: + SourceImage|contains: + - '\Program Files\Windows Defender\' + - '\Program Files\Microsoft Security Client\' + - '\Program Files\CrowdStrike\' + - '\Program Files\SentinelOne\' + - '\Program Files\Cylance\' + - '\Program Files\Carbon Black\' + - '\Program Files\Sophos\' + - '\Program Files\ESET\' + - '\Program Files\Kaspersky\' + - '\Program Files\Trend Micro\' + - '\Program Files (x86)\Trend Micro\' + - '\Program Files\Bitdefender\' + - '\Program Files\Malwarebytes\' + - '\Program Files\Palo Alto Networks\' + filter_werfault: + SourceImage|endswith: '\WerFault.exe' + condition: > + selection_lsass_access + and (selection_suspicious_calltrace or selection_suspicious_source_path) + and not (filter_os_core or filter_security_products or filter_werfault) +falsepositives: + - IT administrators running portable diagnostic tools from non-standard paths that inspect LSASS + - Custom monitoring agents installed outside Program Files that query process information + - Authorized penetration testing tools during sanctioned engagements + - Third-party security products not in the exclusion list (requires environment-specific tuning) +level: medium diff --git a/sigma-rules/lsass-credential-dumping/research.yml b/sigma-rules/lsass-credential-dumping/research.yml new file mode 100644 index 0000000..e87826c --- /dev/null +++ b/sigma-rules/lsass-credential-dumping/research.yml @@ -0,0 +1,58 @@ +title: LSASS Memory Access by Non-System Process (Research Baseline) +id: c08fffe8-ab3c-4e16-abd8-61e648faf95b +status: experimental +description: > + Detects any non-core-OS process opening a handle to lsass.exe with memory-read + access rights. This research-level rule establishes a baseline of all LSASS + access in the environment (AV/EDR products, WerFault, Task Manager, monitoring + tools, and actual attacks) all appear. Run this for one week to build an + environment-specific allowlist of legitimate LSASS accessors before tuning to + Hunt level. The chokepoint is invariant: every credential dumping tool (Mimikatz, + nanodump, comsvcs.dll, ProcDump, HandleKatz, direct syscall loaders) must obtain + a kernel handle to lsass.exe. Sysmon Event ID 10 captures this regardless of the + API path used. +references: + - https://attack.mitre.org/techniques/T1003/001/ + - https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon + - https://github.com/fortra/nanodump +author: "@NovaSky0x1" +date: 2026/03/30 +tags: + - attack.credential_access + - attack.t1003.001 + - attack.t1003 + - detection.maturity.research +logsource: + category: process_access + product: windows +detection: + selection: + TargetImage|endswith: '\lsass.exe' + GrantedAccess|contains: + - '0x1FFFFF' # PROCESS_ALL_ACCESS + - '0x1010' # PROCESS_VM_READ | PROCESS_QUERY_LIMITED_INFORMATION (Mimikatz classic) + - '0x1410' # PROCESS_VM_READ | PROCESS_QUERY_INFORMATION | PROCESS_QUERY_LIMITED_INFORMATION + - '0x0810' # PROCESS_VM_READ | PROCESS_QUERY_INFORMATION (nanodump) + - '0x1038' # PROCESS_VM_READ | PROCESS_VM_WRITE | PROCESS_VM_OPERATION + - '0x1438' # PROCESS_VM_READ | PROCESS_VM_WRITE | PROCESS_VM_OPERATION | PROCESS_QUERY_INFORMATION + - '0x0040' # PROCESS_DUP_HANDLE (handle duplication, HandleKatz, nanodump duphandle mode) + - '0x0010' # PROCESS_VM_READ alone + filter_os_core: + SourceImage|startswith: + - 'C:\Windows\System32\csrss.exe' + - 'C:\Windows\System32\lsass.exe' + - 'C:\Windows\System32\services.exe' + - 'C:\Windows\System32\svchost.exe' + - 'C:\Windows\System32\wininit.exe' + - 'C:\Windows\System32\lsaiso.exe' + - 'C:\Windows\System32\smss.exe' + - 'C:\Windows\System32\winlogon.exe' + condition: selection and not filter_os_core +falsepositives: + - Antivirus and EDR agents performing routine LSASS inspection (MsMpEng.exe, SentinelAgent.exe, CSFalconService.exe, CylanceSvc.exe) + - WerFault.exe collecting crash diagnostics for lsass.exe + - Task Manager (taskmgr.exe) when an administrator manually creates a process dump + - Performance and diagnostic tools (procexp64.exe, procmon64.exe, perfmon.exe) + - WMI provider host (wmiprvse.exe) during certain management queries + - Windows Defender Advanced Threat Protection sensor (MsSense.exe) +level: informational