Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
70 rules
Windows: LSASS Dump (.dmp) Files in CrashDumps Folder
Alerts when an lsass.exe dump (.dmp) appears in the Windows CrashDumps directory under systemprofile.
"@pbssubhash, Huntrule Team"Windowsfile_eventHigh399Free2022-12-08Windows Application Error: LSASS (lsass.exe) Crashed (Event ID 1000)
Alerts on Application Error (Event ID 1000) entries where lsass.exe crashes, using Windows Application event telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh2010Free2022-12-07Windows Process Execution of HandleKatz LSASS Dumper (loader.exe)
Flags HandleKatz-style loader.exe executions that dump LSASS into obfuscated .obf files using --pid and --outfile.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2022-08-18Windows: findstr.exe LSASS keyword matching for process reconnaissance
Alert on find.exe/findstr.exe command lines containing "lsass", indicating potential LSASS-focused reconnaissance.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-08-12Windows Registry: LSA Extensions Multi-SZ DLL Persistence (REG_MULTI_SZ)
Alerts on registry edits to LSA extension DLL entries under LsaSrv\Extensions that can support persistence through lsass.exe loading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh392Free2022-07-21Windows: Suspicious LSASS handle access via svchost.exe call trace to seclogon.dll
Flags svchost.exe attempting LSASS access (granted access 0x14c0) with seclogon.dll in the call trace.
Samir Bousseaden (original elastic rule), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh264Free2022-06-29Windows HandleKatz: Duplicate LSASS Handle via Process Access with Handle Duplication Rights
Flags HandleKatz-style behavior duplicating an existing LSASS handle using PROCESS_DUP_HANDLE and ntdll.dll call trace.
Bhabesh Raj (rule), @thefLinkk, Huntrule TeamWindowsprocess_accessHigh245Free2022-06-27Windows WerFault LSASS Memory Dump File Creation
Flags WerFault dump creation where the dump filename suggests it contains LSASS memory.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh237Free2022-06-27Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh215Free2022-03-12Windows process access indicating potential shellcode injection to lsass.exe
Alerts on high-privilege process access from wmiprvse.exe to lsass.exe consistent with potential shellcode injection behavior.
Bhabesh Raj, Huntrule TeamWindowsprocess_accessMedium90Free2022-03-11Windows Process Creation: TrolleyExpress.exe Used to Access lsass Memory (PID Parameters)
Alerts on command lines using TrolleyExpress.exe PID parameters consistent with LSASS memory dumping on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-02-10Windows LSASS memory access from TrolleyExpress/ProcessDump/dump64 processes
Alerts on Windows processes attempting to access lsass.exe from TrolleyExpress.exe, ProcessDump.exe, or dump64.exe with dump-like access rights.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh141Free2022-02-10Windows LSASS Memory Access Triggered by Source Image Containing 'dump' Keyword
Alerts when a process named with 'dump' requests specific access rights to lsass.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh70Free2022-02-10Windows: Detect XORDump Utility Launch With LSASS Dump and Debug Module Switches
Alerts on xordump.exe spawning with LSASS-targeting and dump-module switches indicative of credential theft.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2022-01-28Windows ProcDump renamed, copied or moved for stealth evasion
Alerts on ProcDump commands that copy/move or rename dump outputs, including LSASS dump filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-01-11