Detection rules › YARA-L

potential lsass process dump via procdump

Severity
high
Type
Detection
Time window
5m
Match by
hostname
Author
Florian Roth (Nextron Systems)
Source
github.com/chronicle/detection-rules

Detects suspicious uses of the SysInternals Procdump utility by using a special command line parameter in combination with the lsass.exe process. This way we are also able to catch cases in which the attacker has renamed the procdump executable. Procdump dump of lsass using minidump or memory dump options. Covers atomic tests 1 and 8

MITRE ATT&CK coverage

TacticTechniques
Credential Access

References

Telemetry coverage

Rule body

// Copyright 2025 Google LLC. Licensed under Apache-2.0.

rule potential_lsass_process_dump_via_procdump {

  meta:
    author = "Florian Roth (Nextron Systems)"
    description = "Detects suspicious uses of the SysInternals Procdump utility by using a special command line parameter in combination with the lsass.exe process. This way we are also able to catch cases in which the attacker has renamed the procdump executable. Procdump dump of lsass using minidump or memory dump options. Covers atomic tests 1 and 8"
    reference = "https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sysinternals_procdump_lsass.yml"
    license = "https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md"
    sigma_uuid = "5afee48e-67dd-4e03-a783-f74259dcf998"
    sigma_status = "stable"
    rule_id = "mr_f7efb1a2-866c-4505-947e-3b06d4240262"
    tactic = "TA0006"
    technique = "T1003.001"
    type = "Detection"
    data_source = "Sysmon"
    platform = "Windows"
    severity = "High"
    priority = "High"
    falsepositives = "Unlikely, because no one should dump an lsass process memory, another tool that uses command line flags similar to ProcDump"

  events:
    $process.metadata.event_type = "PROCESS_LAUNCH"
    (
        strings.contains($process.target.process.command_line, " -ma ") or
        strings.contains($process.target.process.command_line, " -mm ")
    )
    strings.contains(strings.to_lower($process.target.process.command_line), " ls")
    $process.principal.hostname = $hostname

  match:
    $hostname over 5m

   outcome:
    //example usage of specifying test user and hostname to adjust risk score
    $risk_score = max(if($process.principal.user.userid = "user" and $process.principal.hostname = "hostname", 0, 15))
    $principal_process_pid = array_distinct($process.principal.process.pid)
    $principal_process_command_line = array_distinct($process.principal.process.command_line)
    $principal_process_file_sha256 = array_distinct($process.principal.process.file.sha256)
    $principal_process_file_full_path = array_distinct($process.principal.process.file.full_path)
    $principal_process_product_specfic_process_id = array_distinct($process.principal.process.product_specific_process_id)
    $principal_process_parent_process_product_specfic_process_id = array_distinct($process.principal.process.parent_process.product_specific_process_id)
    $target_process_pid = array_distinct($process.target.process.pid)
    $target_process_command_line = array_distinct($process.target.process.command_line)
    $target_process_file_sha256 = array_distinct($process.target.process.file.sha256)
    $target_process_file_full_path = array_distinct($process.target.process.file.full_path)
    $target_process_product_specfic_process_id = array_distinct($process.target.process.product_specific_process_id)
    $principal_user_userid = array_distinct($process.principal.user.userid)
    $log_type = array_distinct(strings.concat($process.metadata.log_type,"/",$process.metadata.product_event_type))

  condition:
    $process
}

YARA-L rule structure

Condition

Fires when at least one $process event in the 5m window.

Events

$process PROCESS_LAUNCH (1, 4688)

  • target.process.command_line contains " -ma "
  • target.process.command_line contains " -mm "
  • target.process.command_line contains " ls"

Match and correlation

Match key
$hostname (principal.hostname)
Within
5m

Outcome

Outcome variables add context to a detection. When the rule generates an alert, $risk_score is displayed with it.

FieldExpression
risk_scoremax(if($process.principal.user.userid = "user" and $process.principal.hostname = "hostname", 0, 15))
principal_process_pidarray_distinct($process.principal.process.pid)
principal_process_command_linearray_distinct($process.principal.process.command_line)
principal_process_file_sha256array_distinct($process.principal.process.file.sha256)
principal_process_file_full_patharray_distinct($process.principal.process.file.full_path)
principal_process_product_specfic_process_idarray_distinct($process.principal.process.product_specific_process_id)
principal_process_parent_process_product_specfic_process_idarray_distinct($process.principal.process.parent_process.product_specific_process_id)
target_process_pidarray_distinct($process.target.process.pid)
target_process_command_linearray_distinct($process.target.process.command_line)
target_process_file_sha256array_distinct($process.target.process.file.sha256)
target_process_file_full_patharray_distinct($process.target.process.file.full_path)
target_process_product_specfic_process_idarray_distinct($process.target.process.product_specific_process_id)
principal_user_useridarray_distinct($process.principal.user.userid)
log_typearray_distinct(strings.concat($process.metadata.log_type,"/",$process.metadata.product_event_type))