Hi,
ENS just reported an "Attempt to Dump Password Hash from SAM Database". The culprit is TiWorker.exe, which if I'm correct is a Windows OS file that relates to updates. I'm not sure if this is a false positive nor how to make that determination so any feedback would be appreciated.
See the event report below:
Analyzer / Detector | |
Analyzer content version | 10.6.0.9906 |
Product name | McAfee Endpoint Security |
Analyzer rule ID | 6143 |
Analyzer rule name | Attempt to Dump Password Hash from SAM Database |
Product version | 10.7.0.1415 |
Feature name | Exploit Prevention |
Threat | |
Action taken | Block |
Threat category | 'Registry' class or access |
Threat event ID | 18060 |
Threat handled | Yes |
Threat name | Attempt to Dump Password Hash from SAM Database |
Threat severity | Critical |
Threat timestamp | 2/27/2020 9:06 AM |
Threat type | Exploit Prevention |
Source | |
Source access time | 1/14/2020 9:30 AM |
Source create time | 1/14/2020 9:30 AM |
Source description | C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3320_none_7f08a1dc21ecea2d\TiWorker.exe -Embedding |
Source file path | C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.3320_none_7f08a1dc21ecea2d |
Source file size | 199680 |
Source modify time | 10/10/2019 11:43 PM |
Source process file hash | bb4aa7d270f529bb5d9c6c16e9b42801 |
Source process name | TiWorker.exe |
Source process signed | Yes |
Source process signer | C=US, S=WASHINGTON, L=REDMOND, O=MICROSOFT CORPORATION, CN=MICROSOFT WINDOWS |
Source user name | NT AUTHORITY\SYSTEM |
Target | |
Target host name | SDET-PDF |
Target name | |
Target path | HKLM\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA\JD\ |
Target signed | No |
Target user name | SYSTEM |
Solved! Go to Solution.
Hi @Remix
Thanks for posting here. This Rule is by default not enabled. Seems like you enabled it at your environment?
it is possible that you are getting false positive. For which I would need verification from content team. Would suggest to open a ticket with us and we can take it further with the content team accordingly.
Hi @Remix
Thanks for posting here. This Rule is by default not enabled. Seems like you enabled it at your environment?
it is possible that you are getting false positive. For which I would need verification from content team. Would suggest to open a ticket with us and we can take it further with the content team accordingly.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA