{"id":"78cc2dd2-7d20-4d32-93ff-057084c38b93","title":"Antivirus Password Dumper Detection","description":"Detects a highly relevant Antivirus alert that reports a password dumper.\nThis event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\n","author":"Florian Roth (Nextron Systems), Arnim Rupp","status":"stable","level":"critical","date":"2018-09-09","modified":"2024-11-02","tags":["attack.credential-access","attack.t1003","attack.t1558","attack.t1003.001","attack.t1003.002"],"technique_ids":["T1003","T1003.001","T1003.002","T1558"],"logsource":{"category":"antivirus"},"falsepositives":["Unlikely"],"references":["https://www.nextron-systems.com/?s=antivirus","https://www.virustotal.com/gui/file/5fcda49ee7f202559a6cbbb34edb65c33c9a1e0bde9fa2af06a6f11b55ded619","https://www.virustotal.com/gui/file/a4edfbd42595d5bddb442c82a02cf0aaa10893c1bf79ea08b9ce576f82749448"],"source_path":"rules/category/antivirus/av_password_dumper.yml","source_sha256":"f8ce7c08df8029c7e4f22d56383ac80091695184394b65d90f901fc56101e331","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/category/antivirus/av_password_dumper.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Antivirus Password Dumper Detection\nid: 78cc2dd2-7d20-4d32-93ff-057084c38b93\nstatus: stable\ndescription: |\n    Detects a highly relevant Antivirus alert that reports a password dumper.\n    This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.\nreferences:\n    - https://www.nextron-systems.com/?s=antivirus\n    - https://www.virustotal.com/gui/file/5fcda49ee7f202559a6cbbb34edb65c33c9a1e0bde9fa2af06a6f11b55ded619\n    - https://www.virustotal.com/gui/file/a4edfbd42595d5bddb442c82a02cf0aaa10893c1bf79ea08b9ce576f82749448\nauthor: Florian Roth (Nextron Systems), Arnim Rupp\ndate: 2018-09-09\nmodified: 2024-11-02\ntags:\n    - attack.credential-access\n    - attack.t1003\n    - attack.t1558\n    - attack.t1003.001\n    - attack.t1003.002\nlogsource:\n    category: antivirus\ndetection:\n    selection:\n        - Signature|startswith: 'PWS'\n        - Signature|contains:\n              - 'Certify'\n              - 'DCSync'\n              - 'DumpCreds'\n              - 'DumpLsass'\n              - 'DumpPert'\n              - 'HTool/WCE'\n              - 'Kekeo'\n              - 'Lazagne'\n              - 'LsassDump'\n              - 'Mimikatz'\n              - 'MultiDump'\n              - 'Nanodump'\n              - 'NativeDump'\n              - 'Outflank'\n              - 'PShlSpy'\n              - 'PSWTool'\n              - 'PWCrack'\n              - 'PWDump'\n              - 'PWS.'\n              - 'PWSX'\n              - 'pypykatz'\n              - 'Rubeus'\n              - 'SafetyKatz'\n              - 'SecurityTool'\n              - 'SharpChrome'\n              - 'SharpDPAPI'\n              - 'SharpDump'\n              - 'SharpKatz'\n              - 'SharpS.' # Sharpsploit, e.g. 530ea2ff9049f5dfdfa0a2e9c27c2e3c0685eb6cbdf85370c20a7bfae49f592d\n              - 'ShpKatz'\n              - 'TrickDump'\n    condition: selection\nfalsepositives:\n    - Unlikely\nlevel: critical\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1003","id":"T1003","name":"OS Credential Dumping","page":"techniques/enterprise/T1003/"},{"key":"enterprise/T1003.001","id":"T1003.001","name":"LSASS Memory","page":"techniques/enterprise/T1003.001/"},{"key":"enterprise/T1003.002","id":"T1003.002","name":"Security Account Manager","page":"techniques/enterprise/T1003.002/"},{"key":"enterprise/T1558","id":"T1558","name":"Steal or Forge Kerberos Tickets","page":"techniques/enterprise/T1558/"}],"data_path":"data/detection-rules/78cc2dd2-7d20-4d32-93ff-057084c38b93.json","kind":"sigma"}
