Password Dumper Remote Thread in LSASS
Description
Detects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage. The process in field Process is the malicious program. A single execution can lead to hundreds of events.
Query · sigma
selection: TargetImage|endswith: \lsass.exe StartModule: '' condition: selection
Known false positives
- Antivirus products