Windows PUA: MemProcFS memory dump mounting via -device
Detects MemProcFS.exe execution with -device on Windows, consistent with mounting memory dumps for potential credential access.
FreeUnreviewedSigmahighv1
windows-pua-memprocfs-memory-dump-mounting-via-device-8a1b2c3d
title: "Windows PUA: MemProcFS memory dump mounting via -device"
id: d6e2fc67-23e4-4d9d-abe1-50ace8abcced
status: experimental
description: This rule flags process creation events where MemProcFS is executed with the -device parameter, indicating it is being used to mount physical memory as a virtual file system. Attackers abuse this capability to access in-memory process data and system structures for credential theft, such as extracting LSASS information or retrieving registry hives and LSA secrets. The detection relies on Windows process creation telemetry, matching MemProcFS.exe identifiers and the presence of -device in the command line.
references:
- https://github.com/ufrisk/MemProcFS
- https://0xdf.gitlab.io/2024/10/05/htb-freelancer.html#
- https://www.huntress.com/blog/curling-for-data-a-dive-into-a-threat-actors-malicious-ttps
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_pua_memprocfs.yml
author: Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team
date: 2026-04-27
tags:
- attack.credential-access
- attack.t1003
- attack.t1003.001
- attack.t1003.004
- attack.t1003.002
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \MemProcFS.exe
- OriginalFileName: MemProcFS.exe
- Description: MemProcFS
selection_cli:
CommandLine|contains: -device
condition: all of selection_*
falsepositives:
- Legitimate use during memory forensics; if not part of authorized analysis, warrants urgent investigation
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_pua_memprocfs/info.yml
license: DRL-1.1
related:
- id: 8a1b2c3d-4e5f-6789-abcd-ef1234567890
type: derived
What it detects
This rule flags process creation events where MemProcFS is executed with the -device parameter, indicating it is being used to mount physical memory as a virtual file system. Attackers abuse this capability to access in-memory process data and system structures for credential theft, such as extracting LSASS information or retrieving registry hives and LSA secrets. The detection relies on Windows process creation telemetry, matching MemProcFS.exe identifiers and the presence of -device in the command line.
Known false positives
- Legitimate use during memory forensics; if not part of authorized analysis, warrants urgent investigation
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.