Update sysmon_unsigned_image_loaded_into_lsass.yml

This commit is contained in:
yugoslavskiy 2019-11-14 00:58:39 +03:00 committed by GitHub
parent 20a5c9498c
commit 01ed5a7135
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -2,6 +2,7 @@ title: Unsigned image loaded into LSASS process
description: Loading unsigned image (DLL, EXE) into LSASS process description: Loading unsigned image (DLL, EXE) into LSASS process
author: Teymur Kheirkhabarov, oscd.community author: Teymur Kheirkhabarov, oscd.community
date: 2019/10/22 date: 2019/10/22
modified: 2019/11/13
references: references:
- https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment - https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
tags: tags:
@ -13,7 +14,7 @@ logsource:
detection: detection:
selection: selection:
EventID: 7 EventID: 7
Image: '*\lsass.exe' Image|endswith: '\lsass.exe'
Signed: 'false' Signed: 'false'
condition: selection condition: selection
falsepositives: falsepositives: