Windows suspicious access to LSASS.exe with dbgcore.dll/dbghelp.dll call trace from uncommon paths

Alerts on suspicious LSASS access from unusual locations when dbgcore.dll or dbghelp.dll appears in the call trace.

FreeReviewedSigma · High · v2
Product
windows
Category
process_access
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-11-27
Updated
2026-07-31
title: Windows suspicious access to LSASS.exe with dbgcore.dll/dbghelp.dll call trace from uncommon paths
id: d2010377-1d9a-401c-afa1-3ad051ed4d96
related:
  - id: 416bc4a2-7217-4519-8dc7-c3271817f1d5
    type: similar
  - id: 9f5c1d59-33be-4e60-bcab-85d2f566effd
    type: derived
status: experimental
description: This rule flags process access to LSASS.exe when the call trace contains dbgcore.dll or dbghelp.dll and the requesting process originates from uncommon filesystem locations. Attackers can use these debugging helper DLLs to perform LSASS memory access and dumping via Windows dump-related APIs. The detection relies on process access telemetry that includes the target image, source image path, and call trace contents to identify potentially malicious access patterns.
references:
  - https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html
  - https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpwritedump
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_access/proc_access_win_susp_dbgcore_dbghelp_load.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2025-11-27
tags:
  - attack.credential-access
  - attack.defense-impairment
  - attack.t1003.001
  - attack.t1685
logsource:
  category: process_access
  product: windows
detection:
  selection_lsass_calltrace:
    TargetImage|endswith: \lsass.exe
    CallTrace|contains:
      - dbgcore.dll
      - dbghelp.dll
  selection_susp_location:
    SourceImage|contains:
      - :\Perflogs\
      - :\Temp\
      - :\Users\Public\
      - \$Recycle.Bin\
      - \AppData\Roaming\
      - \Contacts\
      - \Desktop\
      - \Documents\
      - \Downloads\
      - \Favorites\
      - \Favourites\
      - \inetpub\wwwroot\
      - \Music\
      - \Pictures\
      - \Start Menu\Programs\Startup\
      - \Users\Default\
      - \Videos\
      - \Windows\Temp\
  condition: all of selection_*
falsepositives:
  - Possibly during software installation or update processes
level: high
regression_tests_path: regression_data/rules/windows/process_access/proc_access_win_susp_dbgcore_dbghelp_load/info.yml
license: DRL-1.1