[rule]
description = """
Identifies the modification of the Image File Execution Options SilentProcessExit key that can be abused to dump LSASS
memory via the Windows Error Reporting WerFault.exe. Adversaries may use this technique for credential access.
"""
id = "28969fe6-0ebe-4442-b40c-dbe9b4234f5e"
license = "Elastic License v2"
name = "LSA Dump via SilentProcessExit"
os_list = ["windows"]
reference = [
"https://www.deepinstinct.com/2021/02/16/lsass-memory-dumps-are-stealthier-than-ever-before-part-2/",
]
version = "1.0.32"
query = '''
registry where registry.path : "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\lsass*"
'''
min_endpoint_version = "7.15.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1003"
name = "OS Credential Dumping"
reference = "https://attack.mitre.org/techniques/T1003/"
[[threat.technique.subtechnique]]
id = "T1003.001"
name = "LSASS Memory"
reference = "https://attack.mitre.org/techniques/T1003/001/"
[threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"
[internal]
min_endpoint_version = "7.15.0"