1200KM / sigma-rule
Credential Dumping Tools Service Execution - Security — Sigma Rule
Sigma rule f0d1feba-4344-4ca9-8121-a6c97bd6df52. Credential Dumping Tools Service Execution - Security — Sigma Rule. Detects well-known credential dumping tools execution via service execution events
Rule metadata and linked tags
Author: Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community. Source status: test; severity: high. Source dates: 2017-03-05 / 2022-11-29.
{
"product": "windows",
"service": "security",
"definition": "The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"
}Pinned original Sigma rule · Detection Rule License 1.1
Source SHA-256: 48d774206388684aff25d2e4bce06002addcb805443022b68e6f13cf86d68082
Detection logic
Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.
title: Credential Dumping Tools Service Execution - Security
id: f0d1feba-4344-4ca9-8121-a6c97bd6df52
related:
- id: 4976aa50-8f41-45c6-8b15-ab3fc10e79ed
type: derived
status: test
description: Detects well-known credential dumping tools execution via service execution events
references:
- https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
author: Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community
date: 2017-03-05
modified: 2022-11-29
tags:
- attack.credential-access
- attack.execution
- attack.t1003.001
- attack.t1003.002
- attack.t1003.004
- attack.t1003.005
- attack.t1003.006
- attack.t1569.002
- attack.s0005
logsource:
product: windows
service: security
definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
detection:
selection:
EventID: 4697
ServiceFileName|contains:
- 'cachedump'
- 'dumpsvc'
- 'fgexec'
- 'gsecdump'
- 'mimidrv'
- 'pwdump'
- 'servpw'
condition: selection
falsepositives:
- Legitimate Administrator using credential dumping tool for password recovery
level: high
False positives
- Legitimate Administrator using credential dumping tool for password recovery
Source references
Connected ecosystem references
Exact source-tagged techniques
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1003.005 · Cached Domain Credentials · Detection rules & anomalies
- T1003.006 · DCSync · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
Telemetry review
Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.