Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
49 rules
Windows: Detect LSASS crashes caused by netlogon.dll stack buffer overrun (STATUS_STACK_BUFFER_OVERRUN)
Alerts on lsass.exe crashes blamed on netlogon.dll with STATUS_STACK_BUFFER_OVERRUN (0xc0000409) in Windows Application Error (EventID 1000).
sigmahigh2026-06-02Windows suspicious access to LSASS.exe with dbgcore.dll/dbghelp.dll call trace from uncommon paths
Alerts on suspicious LSASS access from unusual locations when dbgcore.dll or dbghelp.dll appears in the call trace.
sigmaWindowshigh2025-11-27Windows Doppelganger (Doppelanger.exe) LSASS Dump Tool Execution
Alerts on Windows execution of Doppelganger.exe with matching IMPHASH values associated with LSASS dumping.
sigmaWindowshigh2025-07-01Windows Application Error 1000 with lsass.exe and WLDAP32.dll Indicating LDAP Nightmare Attempt (CVE-2024-49113)
Alerts on Windows Application Error (EventID 1000) showing lsass.exe crashing in WLDAP32.dll—potential CVE-2024-49113 exploitation attempt.
sigmahigh2025-01-08Python-Based Tool LSASS Process Access for Credential Dumping (Windows)
Alerts on process-access attempts to lsass.exe with a Python-related call trace and high granted access.
sigmaWindowshigh2023-11-27Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
sigmaWindowshigh2023-10-19Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)
Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.
sigmacritical2023-04-20Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling
Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.
sigmacritical2023-04-20Windows Registry: LSASS Full Dump via WER LocalDumps DumpType=2
Flags registry changes enabling LSASS full memory dumps by setting WER LocalDumps DumpType to 0x2.
sigmaWindowshigh2022-12-08Windows: LSASS Dump (.dmp) Files in CrashDumps Folder
Alerts when an lsass.exe dump (.dmp) appears in the Windows CrashDumps directory under systemprofile.
sigmaWindowshigh2022-12-08Windows Application Error: LSASS (lsass.exe) Crashed (Event ID 1000)
Alerts on Application Error (Event ID 1000) entries where lsass.exe crashes, using Windows Application event telemetry.
sigmaWindowshigh2022-12-07Windows Process Execution of HandleKatz LSASS Dumper (loader.exe)
Flags HandleKatz-style loader.exe executions that dump LSASS into obfuscated .obf files using --pid and --outfile.
sigmaWindowshigh2022-08-18Windows: findstr.exe LSASS keyword matching for process reconnaissance
Alert on find.exe/findstr.exe command lines containing "lsass", indicating potential LSASS-focused reconnaissance.
sigmaWindowshigh2022-08-12Windows Registry: LSA Extensions Multi-SZ DLL Persistence (REG_MULTI_SZ)
Alerts on registry edits to LSA extension DLL entries under LsaSrv\Extensions that can support persistence through lsass.exe loading.
sigmaWindowshigh2022-07-21Windows: Suspicious LSASS handle access via svchost.exe call trace to seclogon.dll
Flags svchost.exe attempting LSASS access (granted access 0x14c0) with seclogon.dll in the call trace.
sigmaWindowshigh2022-06-29Windows HandleKatz: Duplicate LSASS Handle via Process Access with Handle Duplication Rights
Flags HandleKatz-style behavior duplicating an existing LSASS handle using PROCESS_DUP_HANDLE and ntdll.dll call trace.
sigmaWindowshigh2022-06-27Windows WerFault LSASS Memory Dump File Creation
Flags WerFault dump creation where the dump filename suggests it contains LSASS memory.
sigmaWindowshigh2022-06-27Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
sigmaWindowshigh2022-03-12Windows process access indicating potential shellcode injection to lsass.exe
Alerts on high-privilege process access from wmiprvse.exe to lsass.exe consistent with potential shellcode injection behavior.
sigmamedium2022-03-11Windows Process Creation: TrolleyExpress.exe Used to Access lsass Memory (PID Parameters)
Alerts on command lines using TrolleyExpress.exe PID parameters consistent with LSASS memory dumping on Windows.
sigmaWindowshigh2022-02-10