title: WerFault Accassing LSASS id: e5b33f7d-eb93-48b6-9851-09e1e610b6d7 status: test description: Detects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up. references: - https://github.com/helpsystems/nanodump/commit/578116faea3d278d53d70ea932e2bbfe42569507 author: Florian Roth (Nextron Systems) date: 2012/06/27 modified: 2022/10/09 tags: - attack.credential_access - attack.t1003.001 - attack.s0002 logsource: category: process_access product: windows detection: selection: SourceImage|endswith: '\WerFault.exe' TargetImage|endswith: '\lsass.exe' GrantedAccess: '0x1FFFFF' condition: selection falsepositives: - Actual failures in lsass.exe that trigger a crash dump (unlikely) - Unknown cases in which WerFault accesses lsass.exe level: high