Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
49 rules
Windows Security Log LSASS Access by Non-Computer Account Process
Alerts on suspicious LSASS access attempts (4663/4656) targeting lsass.exe by non-system processes using flagged access masks.
sigmaWindowsmedium2019-06-20WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
sigmaWindowshigh2019-05-20Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
sigmaWindowslow2019-02-23Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
sigmaWindowshigh2018-10-30Windows LSASS process access blocked by Attack Surface Reduction (Windows Defender event 1121)
Alerts on windefend EventID 1121 for blocked access to lsass.exe, excluding common benign process callers.
sigmaWindowshigh2018-08-26Windows: SafetyKatz LSASS dump default file indicator (Temp\debug.bin)
Flags Windows file events with a target path ending in \Temp\debug.bin, consistent with SafetyKatz LSASS dump output.
sigmaWindowshigh2018-07-24Windows LSASS Remote Thread Creation Indicative of Password Dumping
Flags Windows remote thread creation targeting lsass.exe, a common pattern in password dumping activity.
sigmaWindowshigh2017-02-19Windows Security: Detect LSASS handle access for SAM_DOMAIN (0x705)
Flags handle opens to lsass.exe with access mask 0x705 targeting SAM_DOMAIN, indicative of credential dumping.
sigmaWindowshigh2017-02-12Windows WerFault Access to lsass.exe Indicative of Credential Dumping Attempts
Alert on WerFault.exe gaining broad access to lsass.exe, consistent with credential dumping attempts.
sigmaWindowshigh2012-06-27