Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
70 rules
Windows LSASS Process Clone Execution Observed
Alerts on process creation where LSASS creates a new LSASS clone, which may indicate credential dumping activity.
Florian Roth (Nextron Systems), Samir Bousseaden, Huntrule TeamWindowsprocess_creationCritical382Free2021-11-27Windows Process Access to LSASS Memory From Suspicious Source Paths
Alerts on processes attempting sensitive access to lsass.exe originating from suspicious/temp directories, using granted access and source path context.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessMedium70Free2021-11-27Windows process access to LSASS.exe with suspicious GrantedAccess flags
Alerts on process access attempts to lsass.exe with GrantedAccess rights commonly linked to credential theft behavior.
Florian Roth, Roberto Rodriguez, Dimitrios Slamaris, Mark Russinovich, Thomas Patzke, Teymur Kheirkhabarov, Sherif Eldeeb, James Dickenson, Aleksey Potapov, oscd.community, Huntrule TeamWindowsprocess_accessMedium402Free2021-11-22Windows LSASS Memory Dump File Creation
Alerts on Windows file creation of LSASS memory dump artifacts identified by high-confidence filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh257Free2021-11-15Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh426Free2021-05-03Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh447Free2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh142Free2021-04-23Windows Registry: SilentProcessExit lsass.exe Monitor Registration for Credential Dumping
Alerts on registry registrations for SilentProcessExit monitoring of lsass.exe, a potential precursor to credential dumping.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical143Free2021-02-26Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_accessHigh171Free2020-10-20Windows PowerShell Remote Thread Into lsass.exe Suggesting Credential Dumping
Alerts when PowerShell creates a remote thread into lsass.exe, indicating possible credential dumping on Windows.
oscd.community, Natalia Shornikova, Huntrule TeamWindowscreate_remote_threadHigh215Free2020-10-06PowerShell Access to LSASS on Windows Suggesting Credential Dumping
Alerts when PowerShell (powershell.exe/pwsh.exe) accesses lsass.exe, indicating potential credential dumping.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_accessMedium90Free2020-10-06Windows: Dumpert Process Dumper Execution via Dumpert.dll or Known MD5
Detects Dumpert execution on Windows via known hash and command line reference to Dumpert.dll for lsass memory dumping.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical185Free2020-02-04Windows Security: Suspicious AccessMask/AccessList Requested on LSASS (lsass.exe) Handle
Flags processes requesting potentially credential-dumping-related access to LSASS based on Security Event 4656/4663.
Roberto Rodriguez, Teymur Kheirkhabarov, Dimitrios Slamaris, Mark Russinovich, Aleksey Potapov, oscd.community (update), Huntrule TeamWindowssecurityMedium184Free2019-11-01Windows Process Creation: LSASS .dmp/related Dump Keywords in Command Line
Alerts on Windows command lines containing LSASS dump keywords and .dmp/MDMP/zip/rar variants.
E.M. Anhaus, Tony Lambert, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2019-10-24Uncommon Outbound Kerberos Port 88 Network Connections (Windows Security Event 5156)
Alerts on rare outbound Kerberos (port 88) connections from non-browser/non-lsass processes using Windows Event 5156.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowssecurityMedium3110Free2019-10-24