refactor: minor changes to procdump rule

This commit is contained in:
Florian Roth
2022-01-11 09:10:05 +01:00
parent 64deb38131
commit 1fad4edfcb
@@ -1,6 +1,6 @@
title: Procdump Evasion
id: 79b06761-465f-4f88-9ef2-150e24d3d737
description: Detects uses of the SysInternals Procdump utility in which procdump or its output get renamed
description: Detects uses of the SysInternals Procdump utility in which procdump or its output get renamed or a dump file is moved ot copied to a different name
status: experimental
references:
- https://twitter.com/mrd0x/status/1480785527901204481
@@ -29,6 +29,7 @@ detection:
selection3:
CommandLine|contains:
- 'copy lsass.exe_' # procdump default pattern e.g. lsass.exe_220111_085234.dmp
- 'move lsass.exe_' # procdump default pattern e.g. lsass.exe_220111_085234.dmp
condition: 1 of selection*
falsepositives:
- Cases in which procdump just gets copied to a different directory without any renaming