cred_dump_tools_dropped_files
Description
Files with well-known filenames (parts of credential dump software or files produced by them) creation
Query · yara_l
events:
$file.metadata.event_type = "FILE_CREATION"
(
re.regex($file.target.file.full_path, `\\(fgdump-log|kirbi|pwdump|pwhashes|wce_ccache|wce_krbtkt)`) nocase or
re.regex($file.target.file.full_path, `\\(cachedump\.exe|cachedump64\.exe|DumpExt\.dll|DumpSvc\.exe|Dumpy\.exe|fgexec\.exe|lsremora\.dll|lsremora64\.dll|NTDS\.out|procdump64\.exe|pstgdump\.exe|pwdump\.exe|SAM\.out|SECURITY\.out|servpw\.exe|servpw64\.exe|SYSTEM\.out|test\.pwd|wceaux\.dll)$`) nocase
)
$file.principal.hostname = $hostname
match:
$hostname over 5m
outcome:
//example usage of specifying test user and hostname to adjust risk score
$risk_score = max(if($file.principal.user.userid = "user" and $file.principal.hostname = "hostname", 0, 15))
$principal_hostname = array_distinct($file.principal.hostname)
$principal_process_pid = array_distinct($file.principal.process.pid)
$principal_process_command_line = array_distinct($file.principal.process.command_line)
$principal_process_file_sha256 = array_distinct($file.principal.process.file.sha256)
$principal_process_file_full_path = array_distinct($file.principal.process.file.full_path)
$principal_process_product_specific_process_id = array_distinct($file.principal.process.product_specific_process_id)
$principal_process_parent_process_product_specific_process_id = array_distinct($file.principal.process.parent_process.product_specific_process_id)
$principal_user_userid = array_distinct($file.principal.user.userid)
$target_file_sha256 = array_distinct($file.target.file.sha256)
$target_file_full_path = array_distinct($file.target.file.full_path)
condition:
$file