Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
49 rules
Windows LSASS memory access from TrolleyExpress/ProcessDump/dump64 processes
Alerts on Windows processes attempting to access lsass.exe from TrolleyExpress.exe, ProcessDump.exe, or dump64.exe with dump-like access rights.
sigmaWindowshigh2022-02-10Windows LSASS Memory Access Triggered by Source Image Containing 'dump' Keyword
Alerts when a process named with 'dump' requests specific access rights to lsass.exe on Windows.
sigmaWindowshigh2022-02-10Windows: Detect XORDump Utility Launch With LSASS Dump and Debug Module Switches
Alerts on xordump.exe spawning with LSASS-targeting and dump-module switches indicative of credential theft.
sigmaWindowshigh2022-01-28Windows ProcDump renamed, copied or moved for stealth evasion
Alerts on ProcDump commands that copy/move or rename dump outputs, including LSASS dump filename patterns.
sigmaWindowshigh2022-01-11Windows LSASS Process Clone Execution Observed
Alerts on process creation where LSASS creates a new LSASS clone, which may indicate credential dumping activity.
sigmaWindowscritical2021-11-27Windows Process Access to LSASS Memory From Suspicious Source Paths
Alerts on processes attempting sensitive access to lsass.exe originating from suspicious/temp directories, using granted access and source path context.
sigmamedium2021-11-27Windows process access to LSASS.exe with suspicious GrantedAccess flags
Alerts on process access attempts to lsass.exe with GrantedAccess rights commonly linked to credential theft behavior.
sigmaWindowsmedium2021-11-22Windows LSASS Memory Dump File Creation
Alerts on Windows file creation of LSASS memory dump artifacts identified by high-confidence filename patterns.
sigmaWindowshigh2021-11-15Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
sigmaWindowshigh2021-05-03Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
sigmaWindowshigh2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
sigmaWindowshigh2021-04-23Windows Registry: SilentProcessExit lsass.exe Monitor Registration for Credential Dumping
Alerts on registry registrations for SilentProcessExit monitoring of lsass.exe, a potential precursor to credential dumping.
sigmaWindowscritical2021-02-26Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
sigmaWindowshigh2020-10-20Windows PowerShell Remote Thread Into lsass.exe Suggesting Credential Dumping
Alerts when PowerShell creates a remote thread into lsass.exe, indicating possible credential dumping on Windows.
sigmaWindowshigh2020-10-06PowerShell Access to LSASS on Windows Suggesting Credential Dumping
Alerts when PowerShell (powershell.exe/pwsh.exe) accesses lsass.exe, indicating potential credential dumping.
sigmamedium2020-10-06Windows: Dumpert Process Dumper Execution via Dumpert.dll or Known MD5
Detects Dumpert execution on Windows via known hash and command line reference to Dumpert.dll for lsass memory dumping.
sigmaWindowscritical2020-02-04Windows Security: Suspicious AccessMask/AccessList Requested on LSASS (lsass.exe) Handle
Flags processes requesting potentially credential-dumping-related access to LSASS based on Security Event 4656/4663.
sigmaWindowsmedium2019-11-01Windows Process Creation: LSASS .dmp/related Dump Keywords in Command Line
Alerts on Windows command lines containing LSASS dump keywords and .dmp/MDMP/zip/rar variants.
sigmaWindowshigh2019-10-24Uncommon Outbound Kerberos Port 88 Network Connections (Windows Security Event 5156)
Alerts on rare outbound Kerberos (port 88) connections from non-browser/non-lsass processes using Windows Event 5156.
sigmaWindowsmedium2019-10-24Windows: Unsigned DLL/EXE Image Loaded Into lsass.exe
Alerts on image loads into lsass.exe where the loaded image is unsigned.
sigmaWindowsmedium2019-10-22