Skip to content

Commit 11eb0fe

Browse files
committed
T1003.001 Update
1 parent 0ae64ea commit 11eb0fe

File tree

2 files changed

+61
-9
lines changed

2 files changed

+61
-9
lines changed

detections/endpoint/windows_possible_credential_dumping.yml

+5-8
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Windows Possible Credential Dumping
22
id: e4723b92-7266-11ec-af45-acde48001122
3-
version: 2
4-
date: '2022-01-27'
3+
version: 3
4+
date: '2022-08-24'
55
author: Michael Haag, Splunk
66
type: TTP
77
datamodel: []
@@ -23,12 +23,8 @@ description: 'The following analytic is an enhanced version of two previous anal
2323
The idea behind using ntdll.dll is to blend in by using native api of ntdll.dll.
2424
For example in sekurlsa module there are many ntdll exported api, like RtlCopyMemory,
2525
used to execute this module which is related to lsass dumping.'
26-
search: '`sysmon` EventCode=10 TargetImage=*lsass.exe GrantedAccess IN ("0x01000",
27-
"0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", "0x1438",
28-
"0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*") | stats
29-
count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, GrantedAccess,
30-
SourceImage, SourceProcessId, SourceUser, TargetUser | rename Computer as dest |
31-
`security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_possible_credential_dumping_filter`'
26+
search: '`sysmon` EventCode=10 TargetImage=*\\lsass.exe GrantedAccess IN ("0x01000", "0x1010", "0x1038", "0x40", "0x1400", "0x1fffff", "0x1410", "0x143a", "0x1438", "0x1000") CallTrace IN ("*dbgcore.dll*", "*dbghelp.dll*", "*ntdll.dll*", "*kernelbase.dll*") NOT SourceUser IN ("NT AUTHORITY\\SYSTEM", "NT AUTHORITY\\NETWORK SERVICE")| stats count min(_time) as firstTime max(_time) as lastTime by, Computer, SourceImage, GrantedAccess, TargetImage, SourceProcessId, SourceUser, TargetUser | rename Computer as dest | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`
27+
| `windows_possible_credential_dumping_filter`'
3228
how_to_implement: To successfully implement this search, you need to be ingesting
3329
logs with the process name, parent process, and command-line executions from your
3430
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
@@ -42,6 +38,7 @@ references:
4238
- https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html
4339
- https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1
4440
- https://docs.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights?redirectedfrom=MSDN
41+
- https://github.com/redcanaryco/AtomicTestHarnesses/blob/master/TestHarnesses/T1003.001_DumpLSASS/DumpLSASS.ps1
4542
tags:
4643
analytic_story:
4744
- Credential Dumping

lookups/hijacklibs.csv

+56-1
Original file line numberDiff line numberDiff line change
@@ -5,13 +5,16 @@ hha.dll,TRUE
55
aclui.dll,TRUE
66
xwtpw32.dll,TRUE
77
xwizards.dll,TRUE
8+
xpsservices.dll,TRUE
89
xolehlp.dll,TRUE
910
xmllite.dll,TRUE
1011
wwapi.dll,TRUE
1112
wwancfg.dll,TRUE
1213
wtsapi32.dll,TRUE
14+
wsmsvc.dll,TRUE
1315
wshelper.dll,TRUE
1416
wshbth.dll,TRUE
17+
wscapi.dll,TRUE
1518
wpdshext.dll,TRUE
1619
wofutil.dll,TRUE
1720
wmsgapi.dll,TRUE
@@ -25,8 +28,10 @@ wlbsctrl.dll,TRUE
2528
wlancfg.dll,TRUE
2629
wlanapi.dll,TRUE
2730
wkscli.dll,TRUE
31+
winsync.dll,TRUE
2832
winsta.dll,TRUE
2933
winsqlite3.dll,TRUE
34+
winscard.dll,TRUE
3035
winrnr.dll,TRUE
3136
winnsi.dll,TRUE
3237
winmm.dll,TRUE
@@ -38,9 +43,11 @@ windowsudk.shellcommon.dll,TRUE
3843
windowsperformancerecordercontrol.dll,TRUE
3944
windowscodecsext.dll,TRUE
4045
windowscodecs.dll,TRUE
46+
windows.ui.immersive.dll,TRUE
4147
windows.storage.search.dll,TRUE
4248
windows.storage.dll,TRUE
4349
winbrand.dll,TRUE
50+
winbio.dll,TRUE
4451
wimgapi.dll,TRUE
4552
whhelper.dll,TRUE
4653
wevtapi.dll,TRUE
@@ -56,13 +63,18 @@ wbemprox.dll,TRUE
5663
vsstrace.dll,TRUE
5764
vssapi.dll,TRUE
5865
virtdisk.dll,TRUE
66+
version.dll,TRUE
67+
vdsutil.dll,TRUE
5968
vaultcli.dll,TRUE
6069
uxtheme.dll,TRUE
6170
uxinit.dll,TRUE
6271
utildll.dll,TRUE
6372
userenv.dll,TRUE
73+
urlmon.dll,TRUE
6474
upshared.dll,TRUE
6575
updatepolicy.dll,TRUE
76+
unattend.dll,TRUE
77+
umpdc.dll,TRUE
6678
uiribbon.dll,TRUE
6779
uireng.dll,TRUE
6880
uiautomationcore.dll,TRUE
@@ -73,6 +85,7 @@ twext.dll,TRUE
7385
ttdrecord.dll,TRUE
7486
tsworkspace.dll,TRUE
7587
tquery.dll,TRUE
88+
tpmcoreprovisioning.dll,TRUE
7689
timesync.dll,TRUE
7790
tdh.dll,TRUE
7891
tbs.dll,TRUE
@@ -87,14 +100,17 @@ ssp_isv.exe_rsaenh.dll,TRUE
87100
ssp.exe_rsaenh.dll,TRUE
88101
srvcli.dll,TRUE
89102
srpapi.dll,TRUE
103+
srmtrace.dll,TRUE
90104
srcore.dll,TRUE
91105
srclient.dll,TRUE
106+
sppcext.dll,TRUE
92107
sppc.dll,TRUE
93108
spp.dll,TRUE
94109
spectrumsyncclient.dll,TRUE
95110
snmpapi.dll,TRUE
96111
slc.dll,TRUE
97112
shell32.dll,TRUE
113+
security.dll,TRUE
98114
secur32.dll,TRUE
99115
schedcli.dll,TRUE
100116
scecli.dll,TRUE
@@ -116,16 +132,24 @@ reagent.dll,TRUE
116132
rasmontr.dll,TRUE
117133
rasman.dll,TRUE
118134
rasgcw.dll,TRUE
135+
rasdlg.dll,TRUE
119136
rasapi32.dll,TRUE
120137
radcui.dll,TRUE
121138
puiapi.dll,TRUE
122139
prvdmofcomp.dll,TRUE
140+
proximityservicepal.dll,TRUE
141+
proximitycommon.dll,TRUE
123142
propsys.dll,TRUE
143+
profapi.dll,TRUE
144+
prntvpt.dll,TRUE
124145
printui.dll,TRUE
146+
powrprof.dll,TRUE
125147
polstore.dll,TRUE
126148
policymanager.dll,TRUE
127149
pnrpnsp.dll,TRUE
150+
playsndsrv.dll,TRUE
128151
pla.dll,TRUE
152+
pkeyhelper.dll,TRUE
129153
peerdistsh.dll,TRUE
130154
pdh.dll,TRUE
131155
pcaui.dll,TRUE
@@ -135,6 +159,7 @@ p2p.dll,TRUE
135159
osuninst.dll,TRUE
136160
osksupport.dll,TRUE
137161
osbaseln.dll,TRUE
162+
opcservices.dll,TRUE
138163
onex.dll,TRUE
139164
omadmapi.dll,TRUE
140165
oleacc.dll,TRUE
@@ -157,19 +182,24 @@ netutils.dll,TRUE
157182
nettrace.dll,TRUE
158183
netshell.dll,TRUE
159184
netsetupapi.dll,TRUE
185+
netprovfw.dll,TRUE
160186
netprofm.dll,TRUE
161187
netplwiz.dll,TRUE
188+
netjoin.dll,TRUE
162189
netiohlp.dll,TRUE
163190
netid.dll,TRUE
191+
netapi32.dll,TRUE
164192
ndfapi.dll,TRUE
165193
ncrypt.dll,TRUE
166194
napinsp.dll,TRUE
167195
mtxclu.dll,TRUE
168196
msxml3.dll,TRUE
169197
mswsock.dll,TRUE
170198
mswb7.dll,TRUE
199+
msvcp110_win.dll,TRUE
171200
msutb.dll,TRUE
172201
mstracer.dll,TRUE
202+
msiso.dll,TRUE
173203
msi.dll,TRUE
174204
msftedit.dll,TRUE
175205
msdtctm.dll,TRUE
@@ -193,13 +223,17 @@ midimap.dll,TRUE
193223
mi.dll,TRUE
194224
mfplat.dll,TRUE
195225
mfcore.dll,TRUE
226+
mfc42u.dll,TRUE
196227
mdmdiagnostics.dll,TRUE
228+
mbaexmlparser.dll,TRUE
197229
mapistub.dll,TRUE
198230
maintenanceui.dll,TRUE
199231
magnification.dll,TRUE
232+
lrwizdll.dll,TRUE
200233
lpksetupproxyserv.dll,TRUE
201234
logoncontroller.dll,TRUE
202235
logoncli.dll,TRUE
236+
lockhostingframework.dll,TRUE
203237
loadperf.dll,TRUE
204238
linkinfo.dll,TRUE
205239
licensingdiagspp.dll,TRUE
@@ -208,21 +242,25 @@ ktmw32.dll,TRUE
208242
ksuser.dll,TRUE
209243
kdstub.dll,TRUE
210244
joinutil.dll,TRUE
245+
iumsdk.dll,TRUE
211246
iumbase.dll,TRUE
212247
isv.exe_rsaenh.dll,TRUE
213248
iscsium.dll,TRUE
214249
iscsidsc.dll,TRUE
215250
iri.dll,TRUE
216251
iphlpapi.dll,TRUE
217252
inproclogger.dll,TRUE
253+
ifsutil.dll,TRUE
218254
ifmon.dll,TRUE
219255
iertutil.dll,TRUE
220256
iedkcs32.dll,TRUE
221257
ieadvpack.dll,TRUE
222258
idstore.dll,TRUE
259+
icmp.dll,TRUE
223260
httpapi.dll,TRUE
224261
hnetmon.dll,TRUE
225262
hid.dll,TRUE
263+
gpapi.dll,TRUE
226264
getuname.dll,TRUE
227265
fxstiff.dll,TRUE
228266
fxsst.dll,TRUE
@@ -231,7 +269,10 @@ fwpuclnt.dll,TRUE
231269
fwpolicyiomgr.dll,TRUE
232270
fwcfg.dll,TRUE
233271
fwbase.dll,TRUE
272+
fvewiz.dll,TRUE
273+
fveskybackup.dll,TRUE
234274
fveapi.dll,TRUE
275+
framedynos.dll,TRUE
235276
fltlib.dll,TRUE
236277
flightsettings.dll,TRUE
237278
firewallapi.dll,TRUE
@@ -247,11 +288,13 @@ esent.dll,TRUE
247288
efsutil.dll,TRUE
248289
efsadu.dll,TRUE
249290
edputil.dll,TRUE
291+
edgeiso.dll,TRUE
250292
eappprxy.dll,TRUE
251293
eappcfg.dll,TRUE
252294
dynamoapi.dll,TRUE
253295
dxva2.dll,TRUE
254296
dxgi.dll,TRUE
297+
dxcore.dll,TRUE
255298
dwrite.dll,TRUE
256299
dwmcore.dll,TRUE
257300
dwmapi.dll,TRUE
@@ -260,8 +303,10 @@ duser.dll,TRUE
260303
dui70.dll,TRUE
261304
dsrole.dll,TRUE
262305
dsreg.dll,TRUE
306+
dsprop.dll,TRUE
263307
dsparse.dll,TRUE
264308
dsclient.dll,TRUE
309+
drvstore.dll,TRUE
265310
drprov.dll,TRUE
266311
dpx.dll,TRUE
267312
dot3cfg.dll,TRUE
@@ -274,6 +319,7 @@ dmoleaututils.dll,TRUE
274319
dmiso8601utils.dll,TRUE
275320
dmenterprisediagnostics.dll,TRUE
276321
dmenrollengine.dll,TRUE
322+
dmcommandlineutils.dll,TRUE
277323
dmcmnutils.dll,TRUE
278324
dmcfgutils.dll,TRUE
279325
dismcore.dll,TRUE
@@ -310,27 +356,35 @@ cscobj.dll,TRUE
310356
cscapi.dll,TRUE
311357
cryptxml.dll,TRUE
312358
cryptui.dll,TRUE
359+
cryptsp.dll,TRUE
313360
cryptdll.dll,TRUE
314361
cryptbase.dll,TRUE
315362
credui.dll,TRUE
363+
coreuicomponents.dll,TRUE
316364
coremessaging.dll,TRUE
365+
coredplus.dll,TRUE
317366
connect.dll,TRUE
367+
configmanager2.dll,TRUE
318368
comdlg32.dll,TRUE
319369
colorui.dll,TRUE
320370
coloradapterclient.dll,TRUE
371+
cmutil.dll,TRUE
321372
cmpbk32.dll,TRUE
322373
clusapi.dll,TRUE
323374
clipc.dll,TRUE
324375
cldapi.dll,TRUE
325376
certenroll.dll,TRUE
377+
certcli.dll,TRUE
326378
cabview.dll,TRUE
327379
cabinet.dll,TRUE
380+
bootux.dll,TRUE
328381
bootmenuux.dll,TRUE
329382
bderepair.dll,TRUE
330383
bcrypt.dll,TRUE
331384
bcp47mrm.dll,TRUE
332385
bcp47langs.dll,TRUE
333386
bcd.dll,TRUE
387+
batmeter.dll,TRUE
334388
avrt.dll,TRUE
335389
authz.dll,TRUE
336390
authfwcfg.dll,TRUE
@@ -340,9 +394,10 @@ atl.dll,TRUE
340394
archiveint.dll,TRUE
341395
appxdeploymentclient.dll,TRUE
342396
appxalluserstore.dll,TRUE
397+
appvpolicy.dll,TRUE
343398
applicationframe.dll,TRUE
344399
apphelp.dll,TRUE
345-
amsi.dll,TRUE
346400
aepic.dll,TRUE
347401
adsldpc.dll,TRUE
348402
activeds.dll,TRUE
403+
amsi.dll,TRUE

0 commit comments

Comments
 (0)