LSASS Memory Read via PPL Bypass


Description

Identifies attempts to access the Local Security Authority Subsystem Service (LSASS) running as a Protected Process and from a non Protected Process. Adversaries may exploit vulnerabilities or leverage vulnerable drivers to bypass LSA protection.

Query · eql

api where process.Ext.api.name == "ReadProcessMemory" and Target.process.name == "lsass.exe" and
 Target.process.Ext.protection == "PsProtectedSignerLsa-Light" and process.executable != null and
  process.pid != 4 and not process.Ext.protection like "PsProtectedSigner*" and
  process.thread.Ext.call_stack_final_user_module.hash.sha256 != null and
  not process.thread.Ext.call_stack_final_user_module.name in ("Unknown", "Undetermined") and
  not (process.executable : "?:\\Program Files\\Sophos\\Sophos File Scanner\\SophosFileScanner.exe" and
       process.code_signature.subject_name : "Sophos Ltd" and process.code_signature.trusted == true and 
       (process.thread.Ext.call_stack_final_user_module.path : "?:\\program files\\sophos\\sophos standalone engine\\*\\savi.dll" or
        process.thread.Ext.call_stack_final_user_module.name : ("Unknown", "Undetermined"))) and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 : "7db3c6b0aab47ccd44a2b0600808c94978e20bf10dcb5c5829b2eb1d66631f00" and
  not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature,
                   $entry, $entry.subject_name : ("Sophos Ltd", "Microsoft Windows Hardware Compatibility Publisher", "Microsoft Windows Software Compatibility Publisher", "Trend Micro, Inc.") and $entry.status : "trusted") and
  not (process.executable : "C:\\Windows\\System32\\WerFault.exe" and
       process.thread.Ext.call_stack_final_user_module.path in ("c:\\windows\\system32\\dbghelp.dll", "c:\\windows\\system32\\faultrep.dll", "c:\\windows\\system32\\wer.dll", "c:\\windows\\system32\\werfault.exe")) and
  not process.thread.Ext.call_stack_final_user_module.path like ("c:\\windows\\assembly\\nativeimages_*.ni.dll") and
  not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $caller, $caller.status == "trusted") and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 in
                                          ("7dcaaa094cc504fbb1dbfc9e4c6a0727370c0cb2c7a3ba5d830a6a2f57ccb483",
                                           "1d6a20444b2dfb3719dbdd4fab61c94f3a799c0a91bb7a02ab527cbbae2dfb98",
                                           "ed4d6fdb6248bcff64e5652cd0c9d79c483bace94c1120dc3128645f00a5e5c4", 
                                           "f51b2842cd6263b5dbef652ac578628bf7706ae5e19853262e75dea212bac257")
Raw source LSASS Memory Read via PPL Bypass · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Identifies attempts to access the Local Security Authority Subsystem Service (LSASS) running as a Protected Process and
from a non Protected Process. Adversaries may exploit vulnerabilities or leverage vulnerable drivers to bypass LSA
protection.
"""
id = "75483a4a-9ce6-4dcb-9ceb-fe9244ce0d34"
license = "Elastic License v2"
name = "LSASS Memory Read via PPL Bypass"
os_list = ["windows"]
reference = [
    "https://itm4n.github.io/lsass-runasppl/",
    "https://www.elastic.co/security-labs/bits-and-bytes-analyzing-bitsloth",
]
version = "1.0.12"

query = '''
api where process.Ext.api.name == "ReadProcessMemory" and Target.process.name == "lsass.exe" and
 Target.process.Ext.protection == "PsProtectedSignerLsa-Light" and process.executable != null and
  process.pid != 4 and not process.Ext.protection like "PsProtectedSigner*" and
  process.thread.Ext.call_stack_final_user_module.hash.sha256 != null and
  not process.thread.Ext.call_stack_final_user_module.name in ("Unknown", "Undetermined") and
  not (process.executable : "?:\\Program Files\\Sophos\\Sophos File Scanner\\SophosFileScanner.exe" and
       process.code_signature.subject_name : "Sophos Ltd" and process.code_signature.trusted == true and 
       (process.thread.Ext.call_stack_final_user_module.path : "?:\\program files\\sophos\\sophos standalone engine\\*\\savi.dll" or
        process.thread.Ext.call_stack_final_user_module.name : ("Unknown", "Undetermined"))) and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 : "7db3c6b0aab47ccd44a2b0600808c94978e20bf10dcb5c5829b2eb1d66631f00" and
  not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature,
                   $entry, $entry.subject_name : ("Sophos Ltd", "Microsoft Windows Hardware Compatibility Publisher", "Microsoft Windows Software Compatibility Publisher", "Trend Micro, Inc.") and $entry.status : "trusted") and
  not (process.executable : "C:\\Windows\\System32\\WerFault.exe" and
       process.thread.Ext.call_stack_final_user_module.path in ("c:\\windows\\system32\\dbghelp.dll", "c:\\windows\\system32\\faultrep.dll", "c:\\windows\\system32\\wer.dll", "c:\\windows\\system32\\werfault.exe")) and
  not process.thread.Ext.call_stack_final_user_module.path like ("c:\\windows\\assembly\\nativeimages_*.ni.dll") and
  not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $caller, $caller.status == "trusted") and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 in
                                          ("7dcaaa094cc504fbb1dbfc9e4c6a0727370c0cb2c7a3ba5d830a6a2f57ccb483",
                                           "1d6a20444b2dfb3719dbdd4fab61c94f3a799c0a91bb7a02ab527cbbae2dfb98",
                                           "ed4d6fdb6248bcff64e5652cd0c9d79c483bace94c1120dc3128645f00a5e5c4", 
                                           "f51b2842cd6263b5dbef652ac578628bf7706ae5e19853262e75dea212bac257")
'''

min_endpoint_version = "8.14.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1211"
name = "Exploitation for Defense Evasion"
reference = "https://attack.mitre.org/techniques/T1211/"


[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1003"
name = "OS Credential Dumping"
reference = "https://attack.mitre.org/techniques/T1003/"
[[threat.technique.subtechnique]]
id = "T1003.001"
name = "LSASS Memory"
reference = "https://attack.mitre.org/techniques/T1003/001/"



[threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"

[internal]
min_endpoint_version = "8.14.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.