LSA Dump via SilentProcessExit


Description

Identifies the modification of the Image File Execution Options SilentProcessExit key that can be abused to dump LSASS memory via the Windows Error Reporting WerFault.exe. Adversaries may use this technique for credential access.

Query · eql

registry where registry.path : "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\lsass*"
Raw source LSA Dump via SilentProcessExit · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Identifies the modification of the Image File Execution Options SilentProcessExit key that can be abused to dump LSASS
memory via the Windows Error Reporting WerFault.exe. Adversaries may use this technique for credential access.
"""
id = "28969fe6-0ebe-4442-b40c-dbe9b4234f5e"
license = "Elastic License v2"
name = "LSA Dump via SilentProcessExit"
os_list = ["windows"]
reference = [
    "https://www.deepinstinct.com/2021/02/16/lsass-memory-dumps-are-stealthier-than-ever-before-part-2/",
]
version = "1.0.32"

query = '''
registry where registry.path : "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\lsass*"
'''

min_endpoint_version = "7.15.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1003"
name = "OS Credential Dumping"
reference = "https://attack.mitre.org/techniques/T1003/"
[[threat.technique.subtechnique]]
id = "T1003.001"
name = "LSASS Memory"
reference = "https://attack.mitre.org/techniques/T1003/001/"



[threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"

[internal]
min_endpoint_version = "7.15.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.