10000 feat: enhance lsass procdump with additional flags and service names by vl43den · Pull Request #5675 · SigmaHQ/sigma · GitHub
[go: up one dir, main page]

Skip to content

Conversation

vl43den
Copy link
Contributor
@vl43den vl43den commented Oct 3, 2025

Summary of the Pull Request

Expanded procdump detection with -mm (mini dump), -mp (miniplus dump) options, added service-names keyiso and samss, added references by @wietze and Michael Haag (Splunk) & adjusted condition. Reopened PR (Original was #5621, so this continues/supersedes it)! @swachchhanda000 corrected the condition in the old instance and @nasbench was in a review process before my force-close.

Changelog

update: Potential LSASS Process Dump Via Procdump - expand flags and service-names detection

Example Log Event

N/A

Fixed Issues

N/A

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

Reopened PR! Updated detection criteria for SysInternals Procdump usage with lsass.exe to include additional command line parameters and modified the last modified date.
@github-actions github-actions bot added Rules Windows Pull request add/update windows related rules labels Oct 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rules Windows Pull request add/update windows related rules
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant
0