Credential Access Detection Rules | Fibratus
Detection rules for Credential Access (MITRE ATT&CK): LSASS memory dumps, SAM/SECURITY hive access, credential manager abuse, and NTLM hash leaks.
Rules in this category
- File access to SAM database
- Credential Manager access via known tools
- LSASS access from unsigned executable
- LSASS handle leak via Seclogon
- LSASS memory dump preparation via SilentProcessExit
- LSASS memory dump via MiniDumpWriteDump
- LSASS memory dump via Windows Error Reporting
- LSASS process clone creation via reflection
- Potential LSASS memory dump
- Potential NTLM hash leak via MS Photos
- Potential NTLM hash leak via shortcut file
- Registry access to SAM database
- Remote thread creation into LSASS
- Sensitive registry hive dump
- Suspicious access to Active Directory domain database
- Suspicious access to Unattended Panther files
- Suspicious access to Windows DPAPI Master Keys
- Suspicious access to Windows Credential Manager files
- Suspicious access to Windows Vault files
- Suspicious LSA secrets registry access
- Suspicious LSASS process access
- Suspicious security package DLL loaded
- Suspicious Vault client DLL load
- Unusual access to SSH keys
- Unusual access to Web Browser Credential stores
- Unusual access to Windows Credential history files