Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
70 rules
Malicious Mimikatz LSASS Credential Dumping via Command Line
This rule detects Mimikatz command modules such as sekurlsa logonpasswords or lsadump on the process command line, the credential harvesting method TrickBot uses through its Mimikatz-based module to dump LSASS memory. These module strings are distinctive to Mimikatz regardless of the binary name. Their presence indicates active credential theft supporting lateral movement.
HuntRule TeamWindowsprocess_creationHigh102Premium2026-07-16Possible Task Manager Access Indicator for Potential LSASS Dump (via process_creation)
This rule detects provides an indicator of a user accessing the task manager in order to eventually dump the LSASS process content using the "Details" tab > right click on "lsass.exe" > Create a dump file.
HuntRule TeamWindowsprocess_creationLow156Premium2026-06-30Malicious LSASS Credential Dump via SilentProcessExit WerFault Abuse
This rule detects registry modifications under the Image File Execution Options SilentProcessExit or GlobalFlag keys for lsass.exe, the mechanism that forces WerFault.exe to write a full memory dump of the process. Adversaries abuse this Windows Error Reporting behavior to dump LSASS and extract credentials without a recognized dumping tool. These keys targeting lsass.exe have no legitimate use.
HuntRule TeamWindowsregistry_setHigh456Premium2026-06-21Malicious LSASS Credential Dump via comsvcs.dll MiniDump by APT28 (via process_creation)
This rule detects use of rundll32 to invoke the MiniDump export of comsvcs.dll against the LSASS process, the credential-access technique documented in CERT-FR analysis of the APT28 intrusion set targeting French entities. Adversaries leverage this signed LOLBin to capture a memory dump containing plaintext and hashed credentials, making early detection critical for stopping privilege escalation and lateral movement.
HuntRule TeamWindowsprocess_creationHigh91Premium2026-06-04Windows: Detect LSASS crashes caused by netlogon.dll stack buffer overrun (STATUS_STACK_BUFFER_OVERRUN)
Alerts on lsass.exe crashes blamed on netlogon.dll with STATUS_STACK_BUFFER_OVERRUN (0xc0000409) in Windows Application Error (EventID 1000).
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsapplicationHigh172Free2026-06-02Malicious LSASS Memory Dump via Rundll32 comsvcs.dll MiniDump
This rule detects rundll32.exe invoking the comsvcs.dll MiniDump export to dump process memory, a LOLBIN LSASS dumping technique documented by Huntress. Attackers first resolve the LSASS process id via tasklist and then dump its memory to harvest plaintext credentials and hashes. Because comsvcs MiniDump has no legitimate administrative use, this is a high-confidence credential-theft signal.
HuntRule TeamWindowsprocess_creationHigh142Premium2026-05-26Malicious LSASS Memory Dump via comsvcs.dll MiniDump (via process_creation)
This rule detects credential theft where rundll32 invokes the MiniDump export of comsvcs.dll to dump the memory of the LSASS process to disk, a technique observed in Akira ransomware intrusions. The resulting dump is later parsed offline to recover plaintext credentials and hashes.
HuntRule TeamWindowsprocess_creationHigh52Premium2026-05-18Windows suspicious access to LSASS.exe with dbgcore.dll/dbghelp.dll call trace from uncommon paths
Alerts on suspicious LSASS access from unusual locations when dbgcore.dll or dbghelp.dll appears in the call trace.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh183Free2025-11-27Windows Doppelganger (Doppelanger.exe) LSASS Dump Tool Execution
Alerts on Windows execution of Doppelganger.exe with matching IMPHASH values associated with LSASS dumping.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh304Free2025-07-01Windows Application Error 1000 with lsass.exe and WLDAP32.dll Indicating LDAP Nightmare Attempt (CVE-2024-49113)
Alerts on Windows Application Error (EventID 1000) showing lsass.exe crashing in WLDAP32.dll—potential CVE-2024-49113 exploitation attempt.
Samuel Monsempes, Huntrule TeamWindowsapplicationHigh133Free2025-01-08Python-Based Tool LSASS Process Access for Credential Dumping (Windows)
Alerts on process-access attempts to lsass.exe with a Python-related call trace and high granted access.
Bhabesh Raj, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_accessHigh2410Free2023-11-27Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsfile_eventHigh368Free2023-10-19Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)
Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationCritical150Free2023-04-20Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling
Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationCritical110Free2023-04-20Windows Registry: LSASS Full Dump via WER LocalDumps DumpType=2
Flags registry changes enabling LSASS full memory dumps by setting WER LocalDumps DumpType to 0x2.
"@pbssubhash, Huntrule Team"Windowsregistry_setHigh252Free2022-12-08