Detection rules › Splunk

ProcDump Credential Harvest (Windows Event Log)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

Mimikatz is largely detected by AntiVirus software.As Procdump is a legitimate Microsoft tool, it's not detected by AntiVirus. The goal is to dump the lsass.exe process, which contains the credentials, and then give this dump to mimikatz.You need Admin rights to use it. Dump the lsass process which contains credentials

MITRE ATT&CK coverage

TacticTechniques
Credential Access

References

Telemetry coverage

Rule body

id: '1083.1125'
title: ProcDump Credential Harvest
description: 'Mimikatz is largely detected by AntiVirus software.As Procdump is a
  legitimate Microsoft tool, it''s not detected by AntiVirus. The goal is to dump
  the lsass.exe process, which contains the credentials, and then give this dump to
  mimikatz.You need Admin rights to use it. Dump the lsass process which contains
  credentials. -- Threat Actor Association: Agrius, Alloy Taurus/Gallium, Antlion,
  BlackCat, FamousSparrow, FIN12, FIN13, Hydrochasma, Lazarus, MuddyWater, TA551,
  Wizard Spider - Software Association: Bazarloader, Conti, Hafnium , IcedID, LockBit,
  NetWalker, Rhysida -- Atomics T1003.001 Test #2 Atomics T1003.001 Test #9'
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` ("procdump" OR "dump64")
  "lsass" | rex field=_raw max_match=2 "(?<file>[a-zA-Z0-9]+\.dmp") | table _time,
  host, user process, file, session_id, signature_id parent_process_name| bin span=30s
  | stats values(*) as * by _time, host |where match(process, "(?i)procdump|dump64")
  AND match(process, "(?i)lsass") | table _time, host, user process, file, session_id,
  signature_id parent_process_name `hec_collect`'
techniques:
- credential-access:os credential dumping:lsass memory
technique_id:
- T1003.001
data_category:
- Windows event logs
references:
- https://attack.mitre.org/techniques/T1003/001/
- https://github.com/LOLBAS-Project/LOLBAS/pull/182/commits/e14a01bbb5c0b06990cd8f6fc85ee5908ae3da32

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_winevent` ("procdump" OR "dump64") "lsass"

Stage 2: rex

| rex field=_raw max_match=2 "(?<file>[a-zA-Z0-9]+\.dmp")

The parser skipped this rex command.

Stage 3: table

| table _time, host, user process, file, session_id, signature_id parent_process_name

Stage 4: bucket

| bin span=30s

Stage 5: stats

| stats values(*) as * by _time, host

Stage 6: where

| where match(process, "(?i)procdump|dump64") AND match(process, "(?i)lsass")

Stage 7: table

| table _time, host, user process, file, session_id, signature_id parent_process_name `hec_collect`

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
processregex_match
  • "(?i)lsass" corpus 2 (splunk 2)
    • "(?i)procdump
    • dump64"
field:"CommandLine" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"procdump"
1"dump64"
1"lsass"