MITRE ATT&CK technique
OS Credential Dumping detection rulesT1003
OS Credential Dumping (T1003) is a MITRE ATT&CK technique in the Credential Access tactic. This page lists the 150 community-maintained Sigma detection rules in the library mapped to T1003 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, opencanary, linux.
Top products
Tactic
Antivirus - Password Dumper Signature
criticalDetects a highly relevant Antivirus alert that reports password dumpers and stealers. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place and check if passwords need to be reset.
antivirus
APT31 Judgement Panda Activity
criticalDetects APT31 Judgement Panda activity as described in the Crowdstrike 2019 Global Threat Report
windows · process_creation
HackTool - Credential Dumping Tools Named Pipe Created
criticalDetects well-known credential dumping tools execution via specific named pipe creation
windows · pipe_created
HackTool - Dumpert Process Dumper Default File
criticalDetects the creation of the default dump file used by Outflank Dumpert tool. A process dumper, which dumps the lsass process memory
windows · file_event
HackTool - Dumpert Process Dumper Execution
criticalDetects the use of Dumpert process dumper, which dumps the lsass.exe process memory
windows · process_creation
HackTool - Inveigh Execution
criticalDetects the use of Inveigh a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool
windows · process_creation
HackTool - QuarksPwDump Dump File
criticalDetects a dump file written by QuarksPwDump password dumper
windows · file_event
HackTool - Rubeus Execution
criticalDetects the execution of the hacktool Rubeus via PE information of command line parameters
windows · process_creation
HackTool - SafetyKatz Execution
criticalDetects the execution of the hacktool SafetyKatz via PE information and default Image name
windows · process_creation
HackTool - Windows Credential Editor (WCE) Execution
criticalDetects the use of Windows Credential Editor (WCE), a popular post-exploitation tool used to extract plaintext passwords, hash, PIN code and Kerberos tickets from memory. It is often used by threat actors for credential dumping and lateral movement within compromised networks.
windows · process_creation
Hacktool Execution - Imphash
criticalDetects the execution of different Windows based hacktools via their import hash (imphash) even if the files have been renamed
windows · process_creation
NotPetya Ransomware Activity
criticalDetects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil
windows · process_creation
Potential Credential Dumping Via LSASS Process Clone
criticalDetects a suspicious LSASS process process clone that could be a sign of credential dumping activity
windows · process_creation
Potential Credential Dumping Via LSASS SilentProcessExit Technique
criticalDetects changes to the Registry in which a monitor program gets registered to dump the memory of the lsass.exe process
windows · registry_event
Potential Russian APT Credential Theft Activity
criticalDetects Russian group activity as described in Global Threat Report 2019 by Crowdstrike
windows · process_creation
WCE wceaux.dll Access
criticalDetects wceaux.dll access while WCE pass-the-hash remote command execution on source host
windows
Windows Credential Editor Registry
criticalDetects the use of Windows Credential Editor (WCE)
windows · registry_event
Copying Sensitive Files with Credential Data
highFiles with well-known filenames (sensitive files with credential data) copying
windows · process_creation
Create Volume Shadow Copy with Powershell
highAdversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information
windows · ps_script
CreateDump Process Dump
highDetects uses of the createdump.exe LOLOBIN utility to dump process memory
windows · process_creation
Cred Dump Tools Dropped Files
highFiles with well-known filenames (parts of credential dump software or files produced by them) creation
windows · file_event
Credential Dumping Activity By Python Based Tool
highDetects LSASS process access for potential credential dumping by a Python-like tool such as LaZagne or Pypykatz.
windows · process_access
Credential Dumping Attempt Via WerFault
highDetects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up.
windows · process_access
Credential Dumping Tools Service Execution - Security
highDetects well-known credential dumping tools execution via service execution events
windows
Credential Dumping Tools Service Execution - System
highDetects well-known credential dumping tools execution via service execution events
windows
Critical Hive In Suspicious Location Access Bits Cleared
highDetects events from the Kernel-General ETW indicating that the access bits of a hive with a system like hive name located in the temp directory have been reset. This occurs when an application tries to access a hive and the hive has not be recognized since the last 7 days (by default). Registry hive dumping utilities such as QuarksPwDump were seen emitting this behavior.
windows
DPAPI Domain Backup Key Extraction
highDetects tools extracting LSA secret DPAPI domain backup key from Domain Controllers
windows
Dumping of Sensitive Hives Via Reg.EXE
highDetects the usage of "reg.exe" in order to dump sensitive registry hives. This includes SAM, SYSTEM and SECURITY hives.
windows · process_creation
Esentutl Volume Shadow Copy Service Keys
highDetects the volume shadow copy service initialization and processing via esentutl. Registry keys such as HKLM\\System\\CurrentControlSet\\Services\\VSS\\Diag\\VolSnap\\Volume are captured.
windows · registry_event
HackTool - CrackMapExec File Indicators
highDetects file creation events with filename patterns used by CrackMapExec.
windows · file_event
HackTool - CrackMapExec Process Patterns
highDetects suspicious process patterns found in logs when CrackMapExec is used
windows · process_creation
HackTool - CreateMiniDump Execution
highDetects the use of CreateMiniDump hack tool used to dump the LSASS process memory for credential extraction on the attacker's machine
windows · process_creation
HackTool - Doppelanger LSASS Dumper Execution
highDetects the execution of the Doppelanger hacktool which is used to dump LSASS memory via process cloning while evading common detection methods
windows · process_creation
HackTool - Generic Process Access
highDetects process access requests from hacktool processes based on their default image name
windows · process_access
HackTool - HandleKatz Duplicating LSASS Handle
highDetects HandleKatz opening LSASS to duplicate its handle to later dump the memory without opening any new handles
windows · process_access
HackTool - HandleKatz LSASS Dumper Execution
highDetects the use of HandleKatz, a tool that demonstrates the usage of cloned handles to Lsass in order to create an obfuscated memory dump of the same
windows · process_creation
HackTool - Impacket File Indicators
highDetects file creation events with filename patterns used by Impacket.
windows · file_event
HackTool - Mimikatz Execution
highDetection well-known mimikatz command line arguments
windows · process_creation
HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump
highDetects default filenames output from the execution of CrackMapExec and Impacket-secretsdump against an endpoint.
windows · file_event
HackTool - Pypykatz Credentials Dumping Activity
highDetects the usage of "pypykatz" to obtain stored credentials. Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database through Windows registry where the SAM database is stored
windows · process_creation
HackTool - Quarks PwDump Execution
highDetects usage of the Quarks PwDump tool via commandline arguments
windows · process_creation
HackTool - Rubeus Execution - ScriptBlock
highDetects the execution of the hacktool Rubeus using specific command line flags
windows · ps_script
HackTool - SafetyKatz Dump Indicator
highDetects default lsass dump filename generated by SafetyKatz.
windows · file_event
HackTool - WSASS Execution
highDetects execution of WSASS, a tool used to dump LSASS memory on Windows systems by leveraging WER's (Windows Error Reporting) WerFaultSecure.EXE to bypass PPL (Protected Process Light) protections.
windows · process_creation
HackTool - XORDump Execution
highDetects suspicious use of XORDump process memory dumping utility
windows · process_creation
Hacktool Execution - PE Metadata
highDetects the execution of different Windows based hacktools via PE metadata (company, product, etc.) even if the files have been renamed
windows · process_creation
Linux Keylogging with Pam.d
highDetect attempt to enable auditing of TTY input
linux
Live Memory Dump Using Powershell
highDetects usage of a PowerShell command to dump the live memory of a Windows machine
windows · ps_script
LSASS Access Detected via Attack Surface Reduction
highDetects Access to LSASS Process
windows
LSASS Access From Potentially White-Listed Processes
highDetects a possible process memory dump that uses a white-listed filename like TrolleyExpress.exe as a way to dump the LSASS process memory without Microsoft Defender interference
windows · process_access
LSASS Dump Keyword In CommandLine
highDetects the presence of the keywords "lsass" and ".dmp" in the commandline, which could indicate a potential attempt to dump or create a dump of the lsass process.
windows · process_creation
Lsass Full Dump Request Via DumpType Registry Settings
highDetects the setting of the "DumpType" registry value to "2" which stands for a "Full Dump". Technique such as LSASS Shtinkering requires this value to be "2" in order to dump LSASS.
windows · registry_set
LSASS Memory Access by Tool With Dump Keyword In Name
highDetects LSASS process access requests from a source process with the "dump" keyword in its image name.
windows · process_access
Lsass Memory Dump via Comsvcs DLL
highDetects adversaries leveraging the MiniDump export function from comsvcs.dll via rundll32 to perform a memory dump from lsass.
windows · process_access
LSASS Process Crashed - Application
highDetects Windows error reporting events where the process that crashed is LSASS (Local Security Authority Subsystem Service). This could be the cause of a provoked crash by techniques such as Lsass-Shtinkering to dump credentials.
windows
LSASS Process Dump Artefact In CrashDumps Folder
highDetects the presence of an LSASS dump file in the "CrashDumps" folder. This could be a sign of LSASS credential dumping. Techniques such as the LSASS Shtinkering have been seen abusing the Windows Error Reporting to dump said process.
windows · file_event
LSASS Process Memory Dump Creation Via Taskmgr.EXE
highDetects the creation of an "lsass.dmp" file by the taskmgr process. This indicates a manual dumping of the LSASS.exe process memory using Windows Task Manager.
windows · file_event
LSASS Process Memory Dump Files
highDetects creation of files with names used by different memory dumping tools to create a memory dump of the LSASS process memory, which contains user credentials.
windows · file_event
Microsoft IIS Connection Strings Decryption
highDetects use of aspnet_regiis to decrypt Microsoft IIS connection strings. An attacker with Microsoft IIS web server access via a webshell or alike can decrypt and dump any hardcoded connection strings, such as the MSSQL service account password using aspnet_regiis command.
windows · process_creation
Microsoft IIS Service Account Password Dumped
highDetects the Internet Information Services (IIS) command-line tool, AppCmd, being used to list passwords
windows · process_creation
Mimikatz Use
highThis method detects mimikatz keywords in different Eventlogs (some of them only appear in older Mimikatz version that are however still used by different threat groups)
windows
NTDS Exfiltration Filename Patterns
highDetects creation of files with specific name patterns seen used in various tools that export the NTDS.DIT for exfiltration.
windows · file_event
NTDS.DIT Creation By Uncommon Parent Process
highDetects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon parent process or directory
windows · file_event
NTDS.DIT Creation By Uncommon Process
highDetects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon process or a process located in a suspicious directory
windows · file_event
OpenCanary - MSSQL Login Attempt Via SQLAuth
highDetects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.
opencanary · application
OpenCanary - MSSQL Login Attempt Via Windows Authentication
highDetects instances where an MSSQL service on an OpenCanary node has had a login attempt using Windows Authentication.
opencanary · application
OpenCanary - MySQL Login Attempt
highDetects instances where a MySQL service on an OpenCanary node has had a login attempt.
opencanary · application
OpenCanary - REDIS Action Command Attempt
highDetects instances where a REDIS service on an OpenCanary node has had an action command attempted.
opencanary · application
Password Dumper Activity on LSASS
highDetects process handle on LSASS process with certain access mask and object type SAM_DOMAIN
windows
Password Dumper Remote Thread in LSASS
highDetects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage. The process in field Process is the malicious program. A single execution can lead to hundreds of events.
windows · create_remote_thread
Possible Impacket SecretDump Remote Activity
highDetect AD credential dumping using impacket secretdump HKTL
windows
Possible Impacket SecretDump Remote Activity - Zeek
highDetect AD credential dumping using impacket secretdump HKTL. Based on the SIGMA rules/windows/builtin/win_impacket_secretdump.yml
zeek
Potential Adplus.EXE Abuse
highDetects execution of "AdPlus.exe", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.
windows · process_creation
Potential Credential Dumping Attempt Using New NetworkProvider - CLI
highDetects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
windows · process_creation
Potential Credential Dumping Attempt Via PowerShell Remote Thread
highDetects remote thread creation by PowerShell processes into "lsass.exe"
windows · create_remote_thread
Potential Credential Dumping Via WER
highDetects potential credential dumping via Windows Error Reporting LSASS Shtinkering technique which uses the Windows Error Reporting to dump lsass
windows · process_creation
Potential Invoke-Mimikatz PowerShell Script
highDetects Invoke-Mimikatz PowerShell script and alike. Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords.
windows · ps_script
Potential LSASS Process Dump Via Procdump
highDetects potential credential harvesting attempts through LSASS memory dumps using ProcDump. This rule identifies suspicious command-line patterns that combine memory dump flags (-ma, -mm, -mp) with LSASS-related process markers. LSASS (Local Security Authority Subsystem Service) contains sensitive authentication data including plaintext passwords, NTLM hashes, and Kerberos tickets in memory. Attackers commonly dump LSASS memory to extract credentials for lateral movement and privilege escalation.
windows · process_creation
Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE
highDetects usage of cmdkey to look for cached credentials on the system
windows · process_creation
Potential SAM Database Dump
highDetects the creation of files that look like exports of the local SAM (Security Account Manager)
windows · file_event
Potential SysInternals ProcDump Evasion
highDetects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name
windows · process_creation
Potential Windows Defender AV Bypass Via Dump64.EXE Rename
highDetects when a user is potentially trying to bypass the Windows Defender AV by renaming a tool to dump64.exe and placing it in the Visual Studio folder. Currently the rule is covering only usage of procdump but other utilities can be added in order to increase coverage.
windows · process_creation
Potentially Suspicious ODBC Driver Registered
highDetects the registration of a new ODBC driver where the driver is located in a potentially suspicious location
windows · registry_set
PowerShell Get-Process LSASS in ScriptBlock
highDetects a Get-Process command on lsass process, which is in almost all cases a sign of malicious activity
windows · ps_script
PowerShell SAM Copy
highDetects suspicious PowerShell scripts accessing SAM hives
windows · process_creation
PPL Tampering Via WerFaultSecure
highDetects potential abuse of WerFaultSecure.exe to dump Protected Process Light (PPL) processes like LSASS or to freeze security solutions (EDR/antivirus). This technique is used by tools such as EDR-Freeze and WSASS to bypass PPL protections and access sensitive information or disable security software. Distinct command line patterns help identify the specific tool: - WSASS usage typically shows: "WSASS.exe WerFaultSecure.exe [PID]" in ParentCommandLine - EDR-Freeze usage typically shows: "EDR-Freeze_[version].exe [PID] [timeout]" in ParentCommandLine Legitimate debugging operations using WerFaultSecure are rare in production environments and should be investigated.
windows · process_creation
Process Access via TrolleyExpress Exclusion
highDetects a possible process memory dump that uses the white-listed Citrix TrolleyExpress.exe filename as a way to dump the lsass process memory
windows · process_creation
Process Memory Dump Via Comsvcs.DLL
highDetects a process memory dump via "comsvcs.dll" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)
windows · process_creation
Process Memory Dump via RdrLeakDiag.EXE
highDetects the use of the Microsoft Windows Resource Leak Diagnostic tool "rdrleakdiag.exe" to dump process memory
windows · process_creation
PUA - DIT Snapshot Viewer
highDetects the use of Ditsnap tool, an inspection tool for Active Directory database, ntds.dit.
windows · process_creation
PUA - Memory Dump Mount Via MemProcFS
highDetects execution of MemProcFS a memory forensics tool with the '-device' parameter. MemProcFS mounts physical memory as a virtual file system, allowing direct access to process memory and system structures. Threat actors were seen abusing this utility to mount memory dumps and then extract sensitive information from processes like LSASS or extract registry hives to obtain credentials, LSA secrets, SAM data, and cached domain credentials. MemProcFS usage that is not part of authorized forensic analysis should be treated as suspicious and warrants further investigation.
windows · process_creation
Registry Hive File Staged Outside Standard User Profile Path
highDetects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard user profile path. These files generally contain various user-specific registry settings and are typically located in the user's profile directory. Staging these files outside of the standard path can be indicative of an attacker attempting to manipulate user registry settings for persistence, privilege escalation, or dump user registry hives for credential harvesting.
windows · file_event
Remote LSASS Process Access Through Windows Remote Management
highDetects remote access to the LSASS process via WinRM. This could be a sign of credential dumping from tools like mimikatz.
windows · process_access
Renamed CreateDump Utility Execution
highDetects uses of a renamed legitimate createdump.exe LOLOBIN utility to dump process memory
windows · process_creation
Sensitive File Dump Via Print.EXE
highDetects the abuse of the Print.exe utility for credential harvesting which involves using Print.Exe to copy sensitive files such as ntds.dit, SAM, SECURITY, or SYSTEM from the Windows directory in order to extract credentials, locally or remotely.
windows · process_creation
Sensitive File Dump Via Wbadmin.EXE
highDetects the dump of highly sensitive files such as "NTDS.DIT" and "SECURITY" hive. Attackers can leverage the "wbadmin" utility in order to dump sensitive files that might contain credential or sensitive information.
windows · process_creation
Sensitive File Recovery From Backup Via Wbadmin.EXE
highDetects the dump of highly sensitive files such as "NTDS.DIT" and "SECURITY" hive. Attackers can leverage the "wbadmin" utility in order to dump sensitive files that might contain credential or sensitive information.
windows · process_creation
Suspicious DumpMinitool Execution
highDetects suspicious ways to use the "DumpMinitool.exe" binary
windows · process_creation
Suspicious Get-ADDBAccount Usage
highDetects suspicious invocation of the Get-ADDBAccount script that reads from a ntds.dit file and may be used to get access to credentials without using any credential dumpers
windows · ps_module
Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
highDetects loading of dbgcore.dll or dbghelp.dll from uncommon locations such as user directories. These DLLs contain the MiniDumpWriteDump function, which can be abused for credential dumping purposes or in some cases for evading EDR/AV detection by suspending processes.
windows · image_load
Suspicious LSASS Access Via MalSecLogon
highDetects suspicious access to LSASS handle via a call trace to "seclogon.dll" with a suspicious access right.
windows · process_access
Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
highDetects suspicious process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace. These DLLs contain functions like MiniDumpWriteDump that can be abused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll, dbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.
windows · process_access
Suspicious Process Patterns NTDS.DIT Exfil
highDetects suspicious process patterns used in NTDS.DIT exfiltration
windows · process_creation
Suspicious Renamed Comsvcs DLL Loaded By Rundll32
highDetects rundll32 loading a renamed comsvcs.dll to dump process memory
windows · image_load
Suspicious SYSTEM User Process Creation
highDetects a suspicious process creation as SYSTEM user (suspicious program or command line parameter)
windows · process_creation
Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded
highDetects the load of dbghelp/dbgcore DLL (used to make memory dumps) by suspicious processes. Tools like ProcessHacker and some attacker tradecract use MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll. As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine.
windows · image_load
Time Travel Debugging Utility Usage
highDetects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.
windows · process_creation
Time Travel Debugging Utility Usage - Image
highDetects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.
windows · image_load
VolumeShadowCopy Symlink Creation Via Mklink
highShadow Copies storage symbolic link creation using operating systems utilities
windows · process_creation
WerFault LSASS Process Memory Dump
highDetects WerFault creating a dump file with a name that indicates that the dump file could be an LSASS process memory, which contains user credentials
windows · file_event
Access To Crypto Currency Wallets By Uncommon Applications
mediumDetects file access requests to crypto currency files by uncommon processes. Could indicate potential attempt of crypto currency wallet stealing.
windows · file_access
Active Directory Replication from Non Machine Account - DcSync Indicator
mediumDetects potential abuse of Active Directory Replication Service (ADRS) from a non machine account to request credentials.
windows
Capture Credentials with Rpcping.exe
mediumDetects using Rpcping.exe to send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.
windows · process_creation
Crash Dump Created By Operating System
mediumDetects "BugCheck" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.
windows
Credential Manager Access By Uncommon Applications
mediumDetects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function
windows · file_access
Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process
mediumDetects the load of dbghelp/dbgcore DLL by a potentially uncommon or potentially suspicious process. The Dbghelp and Dbgcore DLLs export functions that allow for the dump of process memory. Tools like ProcessHacker, Task Manager and some attacker tradecraft use the MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll. As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine. Keep in mind that many legitimate Windows processes and services might load the aforementioned DLLs for debugging or other related purposes. Investigate the CommandLine and the Image location of the process loading the DLL.
windows · image_load
DPAPI Domain Master Key Backup Attempt
mediumDetects anyone attempting a backup for the DPAPI Master Key. This events gets generated at the source and not the Domain Controller.
windows
Dumping Process via Sqldumper.exe
mediumDetects process dump via legitimate sqldumper.exe binary
windows · process_creation
DumpMinitool Execution
mediumDetects the use of "DumpMinitool.exe" a tool that allows the dump of process memory via the use of the "MiniDumpWriteDump"
windows · process_creation
Esentutl Gather Credentials
mediumConti recommendation to its affiliates to use esentutl to access NTDS dumped file. Trickbot also uses this utilities to get MSEdge info via its module pwgrab.
windows · process_creation
File Access Of Signal Desktop Sensitive Data
mediumDetects access to Signal Desktop's sensitive data files: db.sqlite and config.json. The db.sqlite file in Signal Desktop stores all locally saved messages in an encrypted SQLite database, while the config.json contains the decryption key needed to access that data. Since the key is stored in plain text, a threat actor who gains access to both files can decrypt and read sensitive messages without needing the users credentials. Currently the rule only covers the default Signal installation path in AppData\Roaming. Signal Portable installations may use different paths based on user configuration. Additional paths can be added to the selection as needed.
windows
Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)
mediumDetects execution of ntdsutil.exe, which can be used for various attacks against the NTDS database (NTDS.DIT)
windows · process_creation
Loaded Module Enumeration Via Tasklist.EXE
mediumDetects the enumeration of a specific DLL or EXE being used by a binary via "tasklist.exe". This is often used by attackers in order to find the specific process identifier (PID) that is using the DLL in question. In order to dump the process memory or perform other nefarious actions.
windows · process_creation
LSASS Access From Non System Account
mediumDetects potential mimikatz-like tools accessing LSASS from non system account
windows
LSASS Access From Program In Potentially Suspicious Folder
mediumDetects process access to LSASS memory with suspicious access flags and from a potentially suspicious folder
windows · process_access
New Generic Credentials Added Via Cmdkey.EXE
mediumDetects usage of "cmdkey.exe" to add generic credentials. As an example, this can be used before connecting to an RDP session via command line interface.
windows · process_creation
Ntdsutil Abuse
mediumDetects potential abuse of ntdsutil to dump ntds.dit database
windows
Potential Credential Dumping Activity Via LSASS
mediumDetects process access requests to the LSASS process with specific call trace calls and access masks. This behaviour is expressed by many credential dumping tools such as Mimikatz, NanoDump, Invoke-Mimikatz, Procdump and even the Taskmgr dumping feature.
windows · process_access
Potential Credential Dumping Attempt Using New NetworkProvider - REG
mediumDetects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
windows · registry_set
Potential Credential Dumping Attempt Via PowerShell
mediumDetects a PowerShell process requesting access to "lsass.exe", which can be indicative of potential credential dumping attempts
windows · process_access
Potential Exploitation of CVE-2025-5054 or CVE-2025-4598
mediumDetects attempts of an attacker to enable core dumps for set-user-ID (SUID) processes by modifying the system file /proc/sys/fs/suid_dumpable, typically by setting its value to 1 or 2. Enabling this feature allows memory dumps (core dumps) of SUID processes, which usually run with elevated privileges. These dumps may contain sensitive information such as passwords, cryptographic keys or other secrets. CVE-2025-5054: Information leak via core dumps from SUID binaries using apport. CVE-2025-4598: Information disclosure in systemd-coredump due to insecure handling of SUID process memory dumps.
linux · process_creation
Potentially Suspicious AccessMask Requested From LSASS
mediumDetects process handle on LSASS process with certain access mask
windows
Potentially Suspicious GrantedAccess Flags On LSASS
mediumDetects process access requests to LSASS process with potentially suspicious access flags
windows · process_access
Procdump Execution
mediumDetects usage of the SysInternals Procdump utility
windows · process_creation
PUA - AWS TruffleHog Execution
mediumDetects the execution of TruffleHog, a popular open-source tool used for scanning repositories for secrets and sensitive information, within an AWS environment. It has been reported to be used by threat actors for credential harvesting. All detections should be investigated to determine if the usage is authorized by security teams or potentially malicious.
aws
Rare Subscription-level Operations In Azure
mediumIdentifies IPs from which users grant access to other users on azure resources and alerts when a previously unseen source IP address is used.
azure
Shadow Copies Creation Using Operating Systems Utilities
mediumShadow Copies creation using operating systems utilities, possible credential access
windows · process_creation
Suspicious Get-ADReplAccount
mediumThe DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
windows · ps_script
Suspicious Machine Account Replication - DcSync Indicator
mediumDetects suspicious Active Directory Replication Service (ADRS) requests originating from a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller. Under normal operation, only Domain Controllers initiate replication requests carrying the DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account credentials — for example by abusing certificate-based authentication (PKINIT) to impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost), where a temporary machine account is created to request a DC certificate and then used to perform DCSync — they can dump all domain credential material including the krbtgt hash.
windows
Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)
mediumDetects execution of ntdsutil.exe to perform different actions such as restoring snapshots...etc.
windows · process_creation
Transferring Files with Credential Data via Network Shares
mediumTransferring files with well-known filenames (sensitive files with credential data) using network shares
windows
Transferring Files with Credential Data via Network Shares - Zeek
mediumTransferring files with well-known filenames (sensitive files with credential data) using network shares
zeek
Uncommon GrantedAccess Flags On LSASS
mediumDetects process access to LSASS memory with uncommon access flags 0x410 and 0x01410
windows · process_access
Unsigned Image Loaded Into LSASS Process
mediumLoading unsigned image (DLL, EXE) into LSASS process
windows · image_load
Access To Browser Credential Files By Uncommon Applications
lowDetects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage
windows · file_access
Access To Chromium Browsers Sensitive Files By Uncommon Applications
lowDetects file access requests to chromium based browser sensitive files by uncommon processes. Could indicate potential attempt of stealing sensitive information.
windows · file_access
Interesting Service Enumeration Via Sc.EXE
lowDetects the enumeration and query of interesting and in some cases sensitive services on the system via "sc.exe". Attackers often try to enumerate the services currently running on a system in order to find different attack vectors.
windows · process_creation
NTDS.DIT Created
lowDetects creation of a file named "ntds.dit" (Active Directory Database)
windows · file_event
Volume Shadow Copy Mount
lowDetects volume shadow copy mount via Windows event log
windows
VSSAudit Security Event Source Registration
informationalDetects the registration of the security event source VSSAudit. It would usually trigger when volume shadow copy operations happen.
windows