Windows PUA: MemProcFS memory dump mounting via -device

Detects MemProcFS.exe execution with -device on Windows, consistent with mounting memory dumps for potential credential access.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-04-27
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process creation events where MemProcFS is executed with the -device parameter, indicating it is being used to mount physical memory as a virtual file system. Attackers abuse this capability to access in-memory process data and system structures for credential theft, such as extracting LSASS information or retrieving registry hives and LSA secrets. The detection relies on Windows process creation telemetry, matching MemProcFS.exe identifiers and the presence of -device in the command line.

Related detections9 linkedT1003.001 — drag to rearrange
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Windows Event Logs: Mimikatz Keyword Indicators
Malicious Mimikatz Credential Access Module Invocation
Malicious WDigest UseLogonCredential Enablement For Credential Theft
Windows PUA: MemProcFS memory dump mounting via -device
Pivot detection · T1003.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.