{"id":"882fbe50-d8d7-4e29-ae80-0648a8556866","title":"Crash Dump Created By Operating System","description":"Detects \"BugCheck\" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.","author":"Jason Mull","status":"experimental","level":"medium","date":"2025-05-12","modified":"","tags":["attack.credential-access","attack.collection","attack.t1003.002","attack.t1005"],"technique_ids":["T1003.002","T1005"],"logsource":{"product":"windows","service":"system"},"falsepositives":[],"references":["https://www.sans.edu/cyber-research/from-crash-compromise-unlocking-potential-windows-crash-dumps-offensive-security/","https://jasonmull.com/articles/offensive/2025-05-12-windows-crash-dumps-offensive-security/"],"source_path":"rules/windows/builtin/system/microsoft_windows_wer_systemerrorreporting/win_system_crash_dump_created.yml","source_sha256":"abf5d7bac3a4495f6b89736d77e98023b11cede94e3bef540dc8f5a34cb08b47","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/system/microsoft_windows_wer_systemerrorreporting/win_system_crash_dump_created.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Crash Dump Created By Operating System\nid: 882fbe50-d8d7-4e29-ae80-0648a8556866\nrelated:\n    - id: 2ff692c2-4594-41ec-8fcb-46587de769e0\n      type: similar\nstatus: experimental\ndescription: Detects \"BugCheck\" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.\nreferences:\n    - https://www.sans.edu/cyber-research/from-crash-compromise-unlocking-potential-windows-crash-dumps-offensive-security/\n    - https://jasonmull.com/articles/offensive/2025-05-12-windows-crash-dumps-offensive-security/\nauthor: Jason Mull\ndate: 2025-05-12\ntags:\n    - attack.credential-access\n    - attack.collection\n    - attack.t1003.002\n    - attack.t1005\nlogsource:\n    product: windows\n    service: system\ndetection:\n    selection:\n        Provider_Name: 'Microsoft-Windows-WER-SystemErrorReporting'\n        EventID: 1001\n    condition: selection\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1003.002","id":"T1003.002","name":"Security Account Manager","page":"techniques/enterprise/T1003.002/"},{"key":"enterprise/T1005","id":"T1005","name":"Data from Local System","page":"techniques/enterprise/T1005/"}],"data_path":"data/detection-rules/882fbe50-d8d7-4e29-ae80-0648a8556866.json","kind":"sigma"}
