HackTool - HandleKatz LSASS Dumper Execution
Description
Detects the use of HandleKatz, a tool that demonstrates the usage of cloned handles to Lsass in order to create an obfuscated memory dump of the same
Query · sigma
selection_loader_img: Image|endswith: \loader.exe CommandLine|contains: '--pid:' selection_loader_imphash: Hashes|contains: - IMPHASH=38D9E015591BBFD4929E0D0F47FA0055 - IMPHASH=0E2216679CA6E1094D63322E3412D650 selection_flags: CommandLine|contains|all: - '--pid:' - '--outfile:' CommandLine|contains: - .dmp - lsass - .obf - dump condition: 1 of selection_*
Known false positives
- Unknown