Merge PR #4750 from @secDre4mer - Fix false positive with Potential Credential Dumping Activity Via LSASS rule

fix: Potential Credential Dumping Activity Via LSASS - remove legitimate access mask
This commit is contained in:
secDre4mer
2024-03-02 02:28:29 +01:00
committed by GitHub
parent 0108cdc344
commit 46559388e0
@@ -11,7 +11,7 @@ references:
- https://research.splunk.com/endpoint/windows_possible_credential_dumping/
author: Samir Bousseaden, Michael Haag
date: 2019/04/03
modified: 2023/12/13
modified: 2024/03/02
tags:
- attack.credential_access
- attack.t1003.001
@@ -23,7 +23,6 @@ detection:
selection:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|contains:
- '0x1000'
- '0x1038'
- '0x1438'
- '0x143a'