Loading interactive filters…
1200KM / detection
T1003 OS Credential Dumping — Detection Rules
Detection workspace for T1003 OS Credential Dumping: 33 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
- OpenCanary - MSSQL Login Attempt Via SQLAuth · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - MSSQL Login Attempt Via Windows Authentication · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - MySQL Login Attempt · test · high · {"category":"application","product":"opencanary"}
- OpenCanary - REDIS Action Command Attempt · test · high · {"category":"application","product":"opencanary"}
- Antivirus Password Dumper Detection · stable · critical · {"category":"antivirus"}
- PUA - AWS TruffleHog Execution · experimental · medium · {"product":"aws","service":"cloudtrail"}
- Rare Subscription-level Operations In Azure · test · medium · {"product":"azure","service":"activitylogs"}
- Linux Keylogging with Pam.d · test · high · {"product":"linux","service":"auditd"}
- WCE wceaux.dll Access · test · critical · {"product":"windows","service":"security"}
- File Access Of Signal Desktop Sensitive Data · experimental · medium · {"product":"windows","service":"security","definition":"Requirements: System Access Control List (SACL) policy with attributes List folder/read data on Objects"}
- Credential Manager Access By Uncommon Applications · test · medium · {"category":"file_access","product":"windows","definition":"Requirements: Microsoft-Windows-Kernel-File ETW provider"}
- Access To Crypto Currency Wallets By Uncommon Applications · test · medium · {"category":"file_access","product":"windows","definition":"Requirements: Microsoft-Windows-Kernel-File ETW provider"}
- HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump · test · high · {"product":"windows","category":"file_event"}
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location · experimental · high · {"category":"image_load","product":"windows"}
- HackTool - Rubeus Execution - ScriptBlock · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Live Memory Dump Using Powershell · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential Invoke-Mimikatz PowerShell Script · test · high · {"category":"ps_script","product":"windows"}
- Esentutl Gather Credentials · test · medium · {"category":"process_creation","product":"windows"}
- Hacktool Execution - Imphash · test · critical · {"category":"process_creation","product":"windows"}
- Hacktool Execution - PE Metadata · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Rubeus Execution · stable · critical · {"category":"process_creation","product":"windows"}
- Microsoft IIS Service Account Password Dumped · test · high · {"category":"process_creation","product":"windows"}
- Microsoft IIS Connection Strings Decryption · test · high · {"category":"process_creation","product":"windows"}
- Potential Credential Dumping Via LSASS Process Clone · test · critical · {"category":"process_creation","product":"windows"}
- PUA - Memory Dump Mount Via MemProcFS · experimental · high · {"category":"process_creation","product":"windows"}
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI · test · high · {"category":"process_creation","product":"windows"}
- Capture Credentials with Rpcping.exe · test · medium · {"category":"process_creation","product":"windows"}
- Interesting Service Enumeration Via Sc.EXE · test · low · {"product":"windows","category":"process_creation"}
- Shadow Copies Creation Using Operating Systems Utilities · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious SYSTEM User Process Creation · test · high · {"category":"process_creation","product":"windows"}
- Loaded Module Enumeration Via Tasklist.EXE · test · medium · {"product":"windows","category":"process_creation"}
- Potential Credential Dumping Attempt Using New NetworkProvider - REG · test · medium · {"category":"registry_set","product":"windows"}
- Potentially Suspicious ODBC Driver Registered · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
T1003 OS Credential Dumping
MATCH(process_access_to_credential_process OR known_dump_tool_signature OR dump_file_pattern) -> ALERT
Anomaly models
Protected credential memory or stores accessed — T1003 OS Credential Dumping
Comparison unit: process-to-protected-resource relationship.
Expected behavior: only a small approved process set accesses credential resources.
Deviation: first-seen edge or rare process-resource combination.
ATT&CK analytic guidance
Processes accessing LSASS memory or SAM registry hives outside of trusted security tools, often followed by file creation or lateral movement. Detects unauthorized access to sensitive OS subsystems for credential extraction.
Processes opening /proc/*/mem or /proc/*/maps targeting credential-storing services like sshd or login. Behavior often includes high privilege escalation and memory inspection tools such as gcore or gdb.
Unsigned processes accessing system memory or launching known credential scraping tools (e.g., osascript, dylib injections) to access the Keychain or sensitive memory regions.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.