feat(chokepoint): add LSASS Credential Dumping (T1003.001)

New chokepoint covering the kernel-mediated handle request to lsass.exe,
the invariant prerequisite for all credential dumping tools.

- Chokepoint YAML with 3 stages, 24 variations, 7 evolution timeline entries
- Research sigma rule: baseline all non-system LSASS access (process_access)
- Hunt sigma rule: CallTrace + source path behavioral filtering
- Analyst sigma rule: triple-AND (access mask + dump mechanism + non-standard path)
- Emulation script with SeDebugPrivilege handling and PPL detection
- 4 raw log samples, 6 OSINT pivots, CHANGELOG updated
This commit is contained in:
NovaSky
2026-03-30 16:29:09 -04:00
parent 76b2a43004
commit 9b010033d5
6 changed files with 1144 additions and 1 deletions
+13 -1
View File
@@ -2,7 +2,19 @@
All notable changes to this detection chokepoints repository will be documented in this file.
## [2025-02-28] — LOLBAS-Style Restructuring
## [2026-03-30] - LSASS Credential Dumping Chokepoint
### Added
- `chokepoints/credential-access/lsass-credential-dumping.yml` - New chokepoint: LSASS credential dumping (T1003.001)
- `sigma-rules/lsass-credential-dumping/research.yml` - Research-level Sigma rule (baseline all non-system LSASS access via process_access)
- `sigma-rules/lsass-credential-dumping/hunt.yml` - Hunt-level Sigma rule (CallTrace + source path behavioral filtering)
- `sigma-rules/lsass-credential-dumping/analyst.yml` - Analyst-level Sigma rule (triple-AND: access mask + dump mechanism + non-standard source)
- `emulation/lsass-credential-dumping/emulate.ps1` - PowerShell emulation script with SeDebugPrivilege handling and PPL detection
- 24 tool variations tracked (Mimikatz, comsvcs.dll, nanodump, HandleKatz, Cobalt Strike, Sliver, Havoc, Brute Ratel, Mythic, and more)
- 4 raw log samples (EID 10 classic, EID 10 direct syscall, EID 10 handle duplication, EID 1 comsvcs LOLBin)
- 6 OSINT pivot queries (VirusTotal, GitHub, LOLDrivers, ANY.RUN)
## [2025-02-28] - LOLBAS-Style Restructuring
### Added
- `CONTRIBUTING.md` — full contribution guide (schema requirements, PR checklist, what not to submit)
@@ -0,0 +1,657 @@
Name: LSASS Credential Dumping
Id: c7df4fc6-05da-4a67-8dfa-efcd8e2420e2
MitreIds:
- T1003.001
- T1003
- T1547.005
Tactics:
- Credential Access
Techniques:
- 'OS Credential Dumping: LSASS Memory'
- OS Credential Dumping
- 'Boot or Logon Autostart Execution: Security Support Provider'
DetectionPriority: CRITICAL
ThreatPrevalence: VERY HIGH
DetectionDifficulty: MEDIUM
Description: >
To extract plaintext credentials, NTLM hashes, or Kerberos tickets from a live
Windows system, an attacker must read the memory of the Local Security Authority
Subsystem Service (lsass.exe). Windows enforces process isolation at the kernel
level: any tool that reads another process's memory must first obtain a handle via
NtOpenProcess with appropriate access rights. This kernel-mediated handle request
is the chokepoint; it fires regardless of whether the attacker uses Mimikatz,
nanodump, comsvcs.dll, ProcDump, direct syscalls, or any future tool. Even
techniques that bypass userland API hooks (ntdll unhooking, direct syscalls) still
traverse the kernel's ObRegisterCallbacks path, which Sysmon Event ID 10
(ProcessAccess) and ETW Threat Intelligence consume. The attacker cannot read
lsass memory without the kernel granting the handle.
LastUpdated: '2026-03-30'
Author: '@NovaSky0x1'
Chokepoints:
- Stage: Handle Acquisition
Invariant: Any process must request a handle to lsass.exe with memory-read access rights from the Windows kernel.
WhyCantBypass: >
Windows enforces process isolation at the kernel level: NtOpenProcess must be
called to obtain a handle, and the kernel's ObRegisterCallbacks fires for every
handle request regardless of whether the caller used standard APIs or direct
syscalls.
LogSources:
- Sysmon Event ID 10 (ProcessAccess)
- Windows Security Event ID 4656 (Handle Requested)
- ETW Microsoft-Windows-Threat-Intelligence (kernel-level telemetry)
DetectionTier: Research
SigmaRef: sigma-rules/lsass-credential-dumping/research.yml
- Stage: Memory Read
Invariant: The process must read lsass.exe virtual memory to extract credential material using NtReadVirtualMemory or MiniDumpWriteDump.
WhyCantBypass: >
Credential material (NTLM hashes, Kerberos tickets, plaintext passwords cached
by WDigest/SSP) resides in lsass.exe process memory. There is no file or
registry location that contains the same live credential state.
LogSources:
- 'Sysmon Event ID 10 (ProcessAccess: CallTrace field reveals read mechanism)'
- 'Sysmon Event ID 11 (File Create: dump file written to disk)'
DetectionTier: Hunt
SigmaRef: sigma-rules/lsass-credential-dumping/hunt.yml
BypassNote: >
Handle duplication (NtDuplicateObject) allows an attacker to clone an existing
handle to lsass from another process, producing GrantedAccess 0x0040 instead of
the standard read masks. The hunt rule includes this pattern.
- Stage: Credential Extraction
Invariant: The attacker must parse LSASS memory structures or dump file contents to extract usable credentials, producing observable artifacts (either an in-memory read with a suspicious CallTrace, a dump file on disk, or a DLL injected into lsass via SSP).
WhyCantBypass: >
Credential structures in lsass memory use Microsoft's internal SSP format.
The attacker must either parse them in-process (generating the ProcessAccess
event) or write a dump file for offline parsing (generating a FileCreate event).
SSP injection (loading a malicious DLL into lsass) generates an ImageLoaded
event for a DLL outside System32.
LogSources:
- 'Sysmon Event ID 10 (ProcessAccess: GrantedAccess + CallTrace correlation)'
- 'Sysmon Event ID 7 (Image Loaded: SSP DLL injection into lsass)'
- 'Sysmon Event ID 11 (File Create: dump file artifact)'
- 'Sysmon Event ID 1 (Process Creation: LOLBin execution)'
DetectionTier: Analyst
SigmaRef: sigma-rules/lsass-credential-dumping/analyst.yml
Variations:
- Name: Mimikatz (sekurlsa::logonpasswords)
FirstSeen: 2011-Q2
Status: Active
SourceURL: https://github.com/gentilkiwi/mimikatz
Notes: >
The original and most widely documented LSASS credential dumping tool. Opens
lsass.exe with PROCESS_ALL_ACCESS (0x1FFFFF) or PROCESS_VM_READ (0x1010).
Used by virtually every ransomware group and APT. GrantedAccess 0x1010 is the
classic Mimikatz fingerprint.
VariantId: mimikatz-sekurlsa
- Name: comsvcs.dll MiniDump (LOLBin)
FirstSeen: 2019-Q1
Status: Active
SourceURL: https://lolbas-project.github.io/#/OtherMSBinaries/Comsvcs
Notes: >
Living-off-the-land technique using rundll32.exe to call the MiniDump export
from comsvcs.dll (a legitimate Windows DLL). Writes a full process dump of
lsass.exe to disk. Command pattern: rundll32.exe comsvcs.dll MiniDump <pid>
<outfile> full. The MiniDump export name is a fixed Windows API; it cannot
be renamed without recompiling the DLL.
VariantId: comsvcs-minidump-lolbin
- Name: ProcDump (Sysinternals)
FirstSeen: 2016-Q1
Status: Active
SourceURL: https://learn.microsoft.com/en-us/sysinternals/downloads/procdump
Notes: >
Microsoft Sysinternals tool used legitimately for debugging, repurposed for
LSASS dumping. Uses MiniDumpWriteDump API (dbgcore.dll/dbghelp.dll in CallTrace).
Signed by Microsoft, so it bypasses many application whitelisting policies.
VariantId: procdump-sysinternals
- Name: Nanodump
FirstSeen: 2022-Q1
Status: Active
SourceURL: https://github.com/fortra/nanodump
Notes: >
Minimal LSASS dumper designed to evade detection. Uses direct syscalls, handle
duplication, and process forking techniques. GrantedAccess patterns vary: 0x0810
for direct read, 0x0040 for handle duplication mode. Produces UNKNOWN in Sysmon
CallTrace when using direct syscalls.
VariantId: nanodump
- Name: HandleKatz
FirstSeen: 2021-Q3
Status: Active
SourceURL: https://github.com/codewhitesec/HandleKatz
Notes: >
Abuses handle duplication to obtain a cloned handle to lsass.exe from another
process that already holds one. GrantedAccess 0x0040 (PROCESS_DUP_HANDLE).
Designed to evade detections that only look for direct PROCESS_VM_READ handles.
VariantId: handlekatz-dup
- Name: PPLBlade / PPLdump
FirstSeen: 2022-Q3
Status: Active
SourceURL: https://github.com/tastypepperoni/PPLBlade
Notes: >
Bypasses Protected Process Light (PPL) protection on lsass.exe by exploiting
vulnerable signed drivers or ELAM driver abuse. Once PPL is defeated, standard
dump tools work. Detection shifts to the BYOVD/driver load stage (covered by
edr-bypass-techniques) plus the subsequent LSASS access event.
VariantId: pplblade-ppldump
- Name: Task Manager Manual Dump
FirstSeen: 2014-Q1
Status: Active
Notes: >
Built-in Windows capability: right-click lsass.exe in Task Manager and select
"Create dump file." Writes a full memory dump to %TEMP%. Uses 0x1FFFFF
GrantedAccess from taskmgr.exe. Often used by less sophisticated attackers
or during hands-on-keyboard intrusions.
VariantId: task-manager-manual-dump
- Name: SSP Injection (mimilib / memssp)
FirstSeen: 2015-Q1
Status: Active
SourceURL: https://attack.mitre.org/techniques/T1547/005/
Notes: >
Injects a malicious Security Support Provider DLL into lsass.exe via
AddSecurityPackage API or direct registry manipulation (HKLM\SYSTEM\CCS\Control\Lsa\Security Packages).
The DLL logs all future authentication events to a file. Sysmon EID 7
detects the DLL load from a non-System32 path.
VariantId: ssp-injection-mimilib
- Name: Direct Syscall Dumpers (SilentProcessExit, MirrorDump, SafetyKatz)
FirstSeen: 2020-Q2
Status: Active
SourceURL: https://github.com/GhostPack/SafetyKatz
Notes: >
Family of tools that use direct system calls (syscall stubs) to bypass ntdll.dll
userland hooks placed by EDR products. The kernel callback (ObRegisterCallbacks)
still fires, so Sysmon EID 10 still generates, but the CallTrace shows UNKNOWN
instead of ntdll.dll. MirrorDump uses DLL injection into a process with an
existing LSASS handle.
VariantId: direct-syscall-dumpers
- Name: Pypykatz (Python)
FirstSeen: 2019-Q3
Status: Active
SourceURL: https://github.com/skelsec/pypykatz
Notes: >
Pure Python implementation of Mimikatz credential extraction. Can parse LSASS
memory dumps offline or access live LSASS via ctypes. Cross-platform, works on
Linux for parsing dump files obtained from Windows. Overlaps with BYOSI chokepoint
when Python interpreter is brought onto the target.
VariantId: pypykatz-python
- Name: Impacket secretsdump.py (Remote)
FirstSeen: 2016-Q1
Status: Active
SourceURL: https://github.com/fortra/impacket
Notes: >
Remote credential extraction over SMB. Supports multiple modes: DCSync
(replicating credentials via DRSUAPI), remote registry SAM/LSA dump, and
remote LSASS memory read via svcctl service creation. When using the LSASS
read mode, the service runs on the target and dumps locally. Overlaps with
the remote-execution-tools chokepoint for the SMB lateral movement stage.
VariantId: impacket-secretsdump
- Name: CrackMapExec / NetExec (--lsa, --sam)
FirstSeen: 2019-Q2
Status: Active
SourceURL: https://github.com/Pennyw0rth/NetExec
Notes: >
Network-based credential harvesting across multiple hosts. The --lsa and
--sam flags dump credentials remotely via SMB service creation. The LSASS
access event occurs on the target host, not the attacker's machine. Used
heavily in ransomware operations for credential spraying across domains.
VariantId: crackmapexec-netexec
- Name: Cobalt Strike (logonpasswords, hashdump)
FirstSeen: 2014-Q1
Status: Active
Notes: >
Built-in beacon commands for credential theft. logonpasswords injects
Mimikatz reflectively into memory; hashdump reads the SAM hive. Both
generate Sysmon EID 10 for the LSASS access. The source process is the
beacon's host process (often rundll32.exe or a sacrificial process),
producing a non-standard source path in most deployments.
VariantId: cobalt-strike-logonpasswords
- Name: Sliver (creds, sharp-dump)
FirstSeen: 2020-Q1
Status: Active
SourceURL: https://github.com/BishopFox/sliver
Notes: >
Open-source C2 framework from BishopFox. Supports credential dumping via
execute-assembly (loading SharpDump or SharpKatz in-process) and through
built-in BOF (Beacon Object File) execution. The LSASS access originates
from the Sliver implant process, which typically runs from a user-writable
path or injected into a legitimate process.
VariantId: sliver-creds
- Name: Havoc (mimikatz, coffloader)
FirstSeen: 2022-Q3
Status: Active
SourceURL: https://github.com/HavocFramework/Havoc
Notes: >
Open-source C2 framework with built-in Mimikatz integration and COFFLoader
for executing credential dumping BOFs. The LSASS access event comes from
the Havoc demon process. Gaining popularity as a Cobalt Strike alternative
in both red team and threat actor operations.
VariantId: havoc-mimikatz
- Name: Brute Ratel C4 (brc4, credstore)
FirstSeen: 2022-Q1
Status: Active
Notes: >
Commercial adversary simulation tool that has been adopted by ransomware
operators (notably BlackCat/ALPHV). Includes built-in credential harvesting
capabilities. Uses syscall-level evasion techniques similar to nanodump,
producing UNKNOWN in Sysmon CallTrace. Leaked versions circulate in
criminal forums.
VariantId: brute-ratel-credstore
- Name: Mythic (Athena, Apollo agents)
FirstSeen: 2020-Q2
Status: Active
SourceURL: https://github.com/its-a-feature/Mythic
Notes: >
Open-source C2 platform with modular agent architecture. Credential
dumping is implemented through agent-specific modules (Athena, Apollo)
that call MiniDumpWriteDump or use direct syscalls. The source process
varies by agent configuration and injection method.
VariantId: mythic-agents
- Name: Dumpert
FirstSeen: 2019-Q3
Status: Active
SourceURL: https://github.com/outflanknl/Dumpert
Notes: >
One of the first public tools to use direct system calls for LSASS dumping,
bypassing ntdll.dll API hooks. Calls NtOpenProcess and NtCreateFile via
syscall stubs. Produces UNKNOWN in Sysmon CallTrace. Foundational technique
adopted by nanodump and subsequent evasion tools.
VariantId: dumpert-direct-syscall
- Name: SharpKatz / SharpDump (.NET)
FirstSeen: 2019-Q1
Status: Active
SourceURL: https://github.com/GhostPack/SharpDump
Notes: >
C# implementations of credential dumping designed for execute-assembly
workflows in Cobalt Strike, Sliver, and similar frameworks. SharpKatz
reimplements Mimikatz in .NET; SharpDump creates a minidump of LSASS.
Both use MiniDumpWriteDump (dbgcore.dll in CallTrace) and run from
the beacon's process context.
VariantId: sharpkatz-sharpdump-dotnet
- Name: Out-Minidump (PowerShell)
FirstSeen: 2016-Q3
Status: Declining
SourceURL: https://github.com/PowerShellMafia/PowerSploit
Notes: >
PowerShell-based LSASS dump using .NET P/Invoke to call MiniDumpWriteDump.
Part of the PowerSploit toolkit. Generates both a PowerShell script block
log and Sysmon EID 10. Less common now due to AMSI and Script Block Logging
making PowerShell-based attacks more visible.
VariantId: out-minidump-powershell
- Name: LSASS Shtinkering (Process Snapshotting)
FirstSeen: 2022-Q1
Status: Emerging
SourceURL: https://github.com/deepinstinct/Lsass-Shtinkering
Notes: >
Uses PssNtCaptureSnapshot to create a snapshot of the LSASS process, then
reads credentials from the snapshot instead of live memory. The snapshot
API still requires a handle to lsass.exe, so Sysmon EID 10 fires, but
the GrantedAccess mask may differ from standard dump patterns. Some EDR
products do not monitor snapshot operations.
VariantId: lsass-shtinkering-snapshot
- Name: Skeleton Key (SSP Backdoor)
FirstSeen: 2015-Q1
Status: Active
SourceURL: https://attack.mitre.org/software/S0007/
Notes: >
Variant of SSP injection that patches the LSASS authentication flow to
accept a universal "skeleton key" password for any domain account. Unlike
mimilib which logs credentials, Skeleton Key modifies authentication
in-memory. Detected via Sysmon EID 7 (DLL loaded into lsass from
non-System32 path) and anomalous Kerberos authentication patterns.
VariantId: skeleton-key-ssp
- Name: LaZagne
FirstSeen: 2015-Q1
Status: Active
SourceURL: https://github.com/AlessandroZ/LaZagne
Notes: >
Multi-platform credential harvester that extracts passwords from browsers,
databases, mail clients, Wi-Fi, and LSASS. Uses ctypes on Windows to call
OpenProcess against lsass.exe. Cross-platform (Python), often deployed
alongside BYOSI techniques.
VariantId: lazagne-multi-platform
- Name: EDRSandBlast (LSASS dump mode)
FirstSeen: 2022-Q4
Status: Active
SourceURL: https://github.com/wavestone-cdt/EDRSandblast
Notes: >
Combines BYOVD driver exploitation with LSASS credential dumping in a
single tool. Loads a vulnerable driver to blind EDR kernel callbacks, then
dumps LSASS. The driver load is detectable via Sysmon EID 6 (see
edr-bypass-techniques); the LSASS access still generates EID 10 if Sysmon
kernel callbacks survive the patching attempt.
VariantId: edrsandblast-lsass
Prerequisites:
- The attacker must have local administrator or SYSTEM privileges on the target host (LSASS access requires SeDebugPrivilege or equivalent)
- LSASS must not be running as a Protected Process Light (PPL), or the attacker must first bypass PPL (see edr-bypass-techniques)
- Credential Guard (VBS) must not be active, or the attacker must compromise the isolated LSA environment (significantly harder, no known public tools)
- Sysmon or equivalent kernel-level telemetry must be deployed for chokepoint visibility (Security EID 4656 provides partial coverage without Sysmon)
EvolutionTimeline:
- Date: 2011-Q2
Event: Mimikatz released by Benjamin Delpy
Change: >
First publicly available tool for extracting plaintext credentials from LSASS
memory. Used PROCESS_ALL_ACCESS (0x1FFFFF) handle with standard Windows API
calls through ntdll.dll.
DetectionImpact: >
No detection existed. LSASS memory access was not monitored by any standard
Windows audit configuration. Security products relied on signature-based
detection of the Mimikatz binary itself.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2016-Q1
Event: 'LOLBin techniques emerge: ProcDump and comsvcs.dll repurposed for LSASS dumping'
Change: >
Attackers shifted from custom tools to Microsoft-signed binaries (procdump.exe,
rundll32.exe + comsvcs.dll) to bypass application whitelisting and signature
detection. The dump is written to disk for offline parsing.
DetectionImpact: >
Binary signature detection bypassed completely. Detection shifted to process
creation monitoring for known LOLBin command patterns and file creation events
for .dmp files in temp directories.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2019-Q2
Event: Sysmon EID 10 (ProcessAccess) adopted as primary LSASS monitoring source
Change: >
Microsoft Sysinternals added ProcessAccess logging to Sysmon, providing
kernel-level visibility into handle requests targeting lsass.exe. The
GrantedAccess and CallTrace fields became the foundation for behavioral
LSASS access detection independent of specific tool signatures.
DetectionImpact: >
Transformed LSASS monitoring from signature-based to behavior-based. Defenders
could now detect any tool accessing LSASS by its access mask and calling
mechanism rather than its binary name or hash.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2020-Q2
Event: Direct syscall and ntdll unhooking techniques proliferate
Change: >
Tools like SilentProcessExit, MirrorDump, and custom loaders bypass EDR
userland hooks by making system calls directly to the kernel, skipping
ntdll.dll entirely. This produces UNKNOWN in Sysmon CallTrace instead of
the standard ntdll.dll entry.
DetectionImpact: >
EDR products relying on ntdll.dll API hooks lost visibility. Sysmon EID 10
still fires because the kernel ObRegisterCallbacks mechanism operates below
the userland hook layer. UNKNOWN in CallTrace became a detection signal
rather than a blind spot.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2021-Q3
Event: Handle duplication evasion (HandleKatz, nanodump duphandle mode)
Change: >
Instead of directly opening lsass.exe, these tools open a different process
that already holds a handle to lsass, then duplicate that handle via
NtDuplicateObject. This produces GrantedAccess 0x0040 (PROCESS_DUP_HANDLE)
rather than the expected 0x1010 or 0x1FFFFF.
DetectionImpact: >
Detection rules looking only for PROCESS_VM_READ or PROCESS_ALL_ACCESS missed
the duplication pattern. Rules updated to include 0x0040 as a suspicious
GrantedAccess value when targeting lsass.exe from a non-standard source path.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2022-Q3
Event: PPL bypass tools combine BYOVD with LSASS dumping
Change: >
PPLBlade, PPLdump, and similar tools load a vulnerable signed kernel driver
to disable Protected Process Light on lsass.exe before performing the dump.
Two-stage attack: driver load (EID 6) precedes LSASS access (EID 10).
DetectionImpact: >
PPL protection is defeated before the dump occurs, so the LSASS access event
appears normal from an access-rights perspective. Detection requires
correlating the vulnerable driver load with subsequent LSASS access. See
edr-bypass-techniques for the driver load stage.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2024-Q3
Event: LSASS credential dumping remains universal across ransomware groups
Change: >
Kaspersky, Mandiant, and Cisco Talos reports confirm T1003.001 in 5 of 5
major ransomware families (BlackBasta, BlackCat, Akira, Qilin, LockBit).
Tool choice varies (Mimikatz, comsvcs.dll, nanodump, custom tools) but
the LSASS access event is present in every case.
DetectionImpact: >
No new evasion of the kernel-level chokepoint. Tool diversity increased but
behavioral detection via Sysmon EID 10 remained effective across all variants.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
EmulationScript:
File: emulation/lsass-credential-dumping/emulate.ps1
Language: powershell
AtomicRef: T1003.001
Description: Simulates LSASS credential dumping chokepoint stages for detection validation
SafetyNotes: >
Run in an isolated lab VM with Sysmon deployed. Requires Administrator privileges.
Does NOT extract credentials. Opens and immediately closes a handle to lsass.exe
to generate EID 10 telemetry, simulates comsvcs.dll command line for EID 1, and
creates a marker .dmp file for EID 11.
Detections:
- Level: Research
Description: Baseline all non-system processes accessing lsass.exe with memory-read permissions
LogSources:
- Sysmon Event ID 10 (ProcessAccess)
Logic: >
Monitor ProcessAccess events where TargetImage is lsass.exe and GrantedAccess
includes memory-read flags (0x1010, 0x1FFFFF, 0x1410, 0x0810, 0x0040, 0x1038,
0x1438, 0x0010). Filter only core OS processes (csrss.exe, services.exe,
svchost.exe, lsass.exe self-access, lsaiso.exe, wininit.exe, smss.exe,
winlogon.exe). Everything else, including AV/EDR products, WerFault,
and Task Manager, appears in this baseline. Run for one week to establish the
environment-specific set of legitimate LSASS accessors before tuning.
ExpectedFPRate: High
UseCase: >
Detection engineers baselining LSASS access patterns in a new environment.
Identifies which processes normally touch LSASS to build the environment-specific
allowlist needed for Hunt and Analyst rules.
SigmaRule: sigma-rules/lsass-credential-dumping/research.yml
- Level: Hunt
Description: LSASS access with suspicious CallTrace, non-standard source path, or LOLBin dump pattern
LogSources:
- Sysmon Event ID 10 (ProcessAccess)
- Sysmon Event ID 1 (Process Creation)
Logic: >
ProcessAccess to lsass.exe with credential-dump access masks WHERE (A) CallTrace
contains dbgcore.dll or dbghelp.dll (MiniDumpWriteDump, used by comsvcs.dll,
ProcDump, Out-Minidump) or UNKNOWN (direct syscall / ntdll unhooking), OR (B)
SourceImage is in a user-writable path (Temp, Downloads, AppData, ProgramData,
Users\Public), OR (C) Process creation matches LOLBin patterns (rundll32 +
comsvcs + MiniDump, or procdump targeting lsass). Excludes core OS processes,
known AV/EDR paths (Program Files\Windows Defender, CrowdStrike, SentinelOne,
Sophos, etc.), and WerFault.
ExpectedFPRate: Medium
UseCase: >
Active threat hunting for credential dumping. Periodic sweeps during incident
response or campaign investigations. CallTrace analysis separates legitimate
security product access from dump tooling behavior.
SigmaRule: sigma-rules/lsass-credential-dumping/hunt.yml
- Level: Analyst
Description: Non-standard process accessing LSASS with dump mechanism fingerprint and credential-dump access rights
LogSources:
- Sysmon Event ID 10 (ProcessAccess)
Logic: >
ProcessAccess to lsass.exe with credential-dump access mask (0x1FFFFF,
0x1010, 0x1410, 0x0810, 0x1038, 0x1438) AND CallTrace shows
MiniDumpWriteDump (dbgcore.dll, dbghelp.dll) or direct syscall (UNKNOWN)
AND source process is outside System32 and Program Files. This triple-AND
eliminates virtually all legitimate LSASS access; AV/EDR runs from Program
Files with clean CallTraces. A secondary selection covers handle duplication
(GrantedAccess 0x0040) targeting lsass from non-standard paths, catching the
HandleKatz and nanodump duphandle evasion technique. Supplementary detections
for comsvcs.dll MiniDump LOLBin (process_creation), SSP injection
(image_load), and dump file artifacts (file_event) should be deployed as
companion SIEM rules for additional coverage across event types.
ExpectedFPRate: Low
UseCase: >
Automated SOC alerting. Direct escalation to Tier 2/IR. If this fires,
assume credential compromise and begin containment (isolate host, reset
exposed credentials, check for lateral movement via pass-the-hash).
SigmaRule: sigma-rules/lsass-credential-dumping/analyst.yml
Intel:
- Name: 'MITRE ATT&CK: T1003.001, OS Credential Dumping: LSASS Memory'
Tier: primary
URL: https://attack.mitre.org/techniques/T1003/001/
Description: >
Primary technique definition. Documents real-world procedures by Mimikatz,
ProcDump, Windows Task Manager, and comsvcs.dll. Lists mitigations including
Credential Guard and PPL.
- Name: 'Microsoft: Credential Guard Overview'
Tier: supporting
URL: https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/
Description: >
Microsoft's documentation on Credential Guard (Virtualization Based Security).
When deployed, isolates LSASS credential material into a separate virtual
machine, preventing direct memory read attacks entirely. The chokepoint
detection remains relevant for environments without Credential Guard.
- Name: 'Sysmon: Event ID 10 ProcessAccess'
Tier: supporting
URL: https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
Description: >
Sysmon documentation covering ProcessAccess event generation. Critical for
understanding GrantedAccess masks, CallTrace format, and configuration
requirements for LSASS monitoring.
- Name: 'Fortra: Nanodump'
Tier: supporting
URL: https://github.com/fortra/nanodump
Description: >
Source code for nanodump, a minimal LSASS dumper demonstrating direct syscall,
handle duplication, and process forking evasion techniques. Essential reference
for understanding modern credential dump evasion and why GrantedAccess 0x0040
and UNKNOWN CallTrace patterns must be included in detection rules.
RelatedChokepoints:
- browser-credential-theft
- edr-bypass-techniques
- remote-execution-tools
OsintSources:
- Platform: VirusTotal Intelligence
Query: 'behavior_processes:"lsass" behavior:"NtOpenProcess" tag:cred-stealer'
Notes: >
Finds malware samples that access lsass.exe during sandbox execution. Pivot
to the behavior tab to extract GrantedAccess patterns and dump methodology
used by each sample. Cross-reference with CallTrace values to identify
new evasion techniques.
- Platform: VirusTotal Intelligence
Query: 'content:"sekurlsa" OR content:"MiniDumpWriteDump" OR content:"comsvcs" positives:5+'
Notes: >
Finds samples containing known credential dump strings. Useful for tracking
new Mimikatz variants, custom dump tools, and LOLBin abuse scripts that
reference comsvcs.dll MiniDump.
- Platform: GitHub Code Search
Query: '"NtOpenProcess" "lsass" language:C OR language:C++'
Notes: >
Finds new credential dumping tool source code. Monitor for novel evasion
techniques: direct syscall wrappers, handle duplication implementations,
and process forking methods that may require detection rule updates.
- Platform: GitHub Code Search
Query: '"MiniDumpWriteDump" "lsass" OR "sekurlsa" language:C#'
Notes: >
Finds .NET-based credential dump tools (SharpKatz, SafetyKatz, SharpDump).
These generate dbgcore.dll in CallTrace, confirming analyst rule coverage.
- Platform: LOLDrivers
Query: https://www.loldrivers.io/
Notes: >
Database of known vulnerable kernel drivers used for BYOVD attacks. PPL
bypass tools (PPLBlade, PPLdump) require loading a vulnerable driver before
dumping LSASS. Cross-reference with edr-bypass-techniques chokepoint for
driver load detection coverage.
- Platform: ANY.RUN
Query: 'suricata:"lsass" OR commandline:"sekurlsa" OR commandline:"comsvcs"'
Notes: >
Sandbox search for samples that interact with lsass.exe during execution.
ANY.RUN provides process tree visualization showing the parent-child chain
and GrantedAccess values, useful for building detection rule context.
References:
- https://attack.mitre.org/techniques/T1003/001/
- https://attack.mitre.org/techniques/T1003/
- https://github.com/fortra/nanodump
- https://github.com/codewhitesec/HandleKatz
- https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
- https://www.blackhillsinfosec.com/red-teamers-cookbook-byoi-bring-your-own-interpreter/
RawLogs:
- Source: Microsoft-Windows-Sysmon/Operational
EventId: 10
Description: 'Mimikatz-style LSASS handle acquisition: classic 0x1010 access mask from user-writable path'
MatchedRules:
- Research
- Hunt
- Analyst
Sample: >
EventID: 10 (ProcessAccess)
UtcTime: 2025-11-14 02:31:18.442
SourceProcessGUID: {a1b2c3d4-5e6f-7890-abcd-ef0123456789}
SourceProcessId: 7284
SourceImage: C:\Users\jsmith\AppData\Local\Temp\procdump64.exe
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
TargetProcessId: 672
TargetImage: C:\Windows\System32\lsass.exe
GrantedAccess: 0x1010
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\Windows\SYSTEM32\dbgcore.dll+6350|C:\Users\jsmith\AppData\Local\Temp\procdump64.exe+1f234
- Source: Microsoft-Windows-Sysmon/Operational
EventId: 10
Description: 'Direct syscall LSASS access: UNKNOWN in CallTrace indicates ntdll hook bypass'
MatchedRules:
- Research
- Hunt
- Analyst
Sample: >
EventID: 10 (ProcessAccess)
UtcTime: 2025-11-14 02:44:07.891
SourceProcessGUID: {a1b2c3d4-9a8b-7c6d-5e4f-3a2b1c0d9e8f}
SourceProcessId: 3412
SourceImage: C:\Users\jsmith\Downloads\update.exe
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
TargetProcessId: 672
TargetImage: C:\Windows\System32\lsass.exe
GrantedAccess: 0x1FFFFF
CallTrace: UNKNOWN
- Source: Microsoft-Windows-Sysmon/Operational
EventId: 10
Description: 'Handle duplication targeting LSASS: HandleKatz/nanodump evasion with GrantedAccess 0x0040'
MatchedRules:
- Analyst
Sample: >
EventID: 10 (ProcessAccess)
UtcTime: 2025-11-14 03:02:55.103
SourceProcessGUID: {a1b2c3d4-1122-3344-5566-778899aabbcc}
SourceProcessId: 5890
SourceImage: C:\ProgramData\staging\svcloader.exe
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
TargetProcessId: 672
TargetImage: C:\Windows\System32\lsass.exe
GrantedAccess: 0x0040
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\ProgramData\staging\svcloader.exe+a238
- Source: Microsoft-Windows-Sysmon/Operational
EventId: 1
Description: 'comsvcs.dll MiniDump LOLBin: rundll32 invoking MiniDump export for LSASS dump'
MatchedRules:
- Hunt
Sample: >
EventID: 1 (Process Create)
UtcTime: 2025-11-14 03:15:22.667
ProcessGUID: {a1b2c3d4-aabb-ccdd-eeff-001122334455}
ProcessId: 8844
Image: C:\Windows\System32\rundll32.exe
CommandLine: rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
ParentProcessGUID: {a1b2c3d4-5566-7788-99aa-bbccddeeff00}
ParentProcessId: 4120
ParentImage: C:\Windows\System32\cmd.exe
ParentCommandLine: cmd.exe /c rundll32.exe comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
TheConstant: A process must open a kernel-mediated handle to lsass.exe and read its virtual memory to extract credential material
@@ -0,0 +1,240 @@
#Requires -Version 5.1
#Requires -RunAsAdministrator
# MITRE ATT&CK: T1003.001, OS Credential Dumping: LSASS Memory
# Simulates LSASS credential dumping chokepoint stages: handle acquisition, memory read, and dump artifact.
# Does NOT extract credentials; uses safe API calls to generate detection telemetry only.
[CmdletBinding()]
param(
[switch]$SkipDumpFile,
[switch]$CleanupOnly,
[string]$DumpPath = (Join-Path $env:TEMP "lsass_emu_$(Get-Random).dmp")
)
Set-StrictMode -Version Latest
$ErrorActionPreference = 'Continue'
function Write-Step ([string]$Msg) { Write-Host "[*] $Msg" -ForegroundColor Cyan }
function Write-Ok ([string]$Msg) { Write-Host "[+] $Msg" -ForegroundColor Green }
function Write-Warn ([string]$Msg) { Write-Host "[!] $Msg" -ForegroundColor Yellow }
function Remove-Artefacts {
if (Test-Path $DumpPath) {
Remove-Item -Path $DumpPath -Force -ErrorAction SilentlyContinue
Write-Ok "Removed dump artefact: $DumpPath"
} else {
Write-Warn "No artefacts found at $DumpPath"
}
}
if ($CleanupOnly) { Remove-Artefacts; exit 0 }
Write-Host ""
Write-Host "=== LSASS Credential Dumping Emulation ===" -ForegroundColor Magenta
Write-Host " T1003.001 | Detection Chokepoints Project" -ForegroundColor DarkGray
Write-Host ""
Write-Warn "This script generates detection telemetry ONLY."
Write-Warn "No credentials are extracted. No memory is parsed."
Write-Warn "Requires Administrator privileges for SeDebugPrivilege."
Write-Host ""
# ─── Enable SeDebugPrivilege ────────────────────────────────────────────────
Write-Step "Enabling SeDebugPrivilege (required for LSASS handle access)"
Add-Type -TypeDefinition @'
using System;
using System.Diagnostics;
using System.Runtime.InteropServices;
public class LsassChokepointEmulation {
[DllImport("kernel32.dll", SetLastError = true)]
public static extern IntPtr OpenProcess(
uint dwDesiredAccess, bool bInheritHandle, int dwProcessId);
[DllImport("kernel32.dll", SetLastError = true)]
[return: MarshalAs(UnmanagedType.Bool)]
public static extern bool CloseHandle(IntPtr hObject);
[DllImport("advapi32.dll", SetLastError = true)]
[return: MarshalAs(UnmanagedType.Bool)]
public static extern bool OpenProcessToken(
IntPtr ProcessHandle, uint DesiredAccess, out IntPtr TokenHandle);
[DllImport("advapi32.dll", SetLastError = true, CharSet = CharSet.Auto)]
[return: MarshalAs(UnmanagedType.Bool)]
public static extern bool LookupPrivilegeValue(
string lpSystemName, string lpName, out long lpLuid);
[DllImport("advapi32.dll", SetLastError = true)]
[return: MarshalAs(UnmanagedType.Bool)]
public static extern bool AdjustTokenPrivileges(
IntPtr TokenHandle, bool DisableAllPrivileges,
ref TOKEN_PRIVILEGES NewState, int BufferLength,
IntPtr PreviousState, IntPtr ReturnLength);
[DllImport("kernel32.dll")]
public static extern IntPtr GetCurrentProcess();
[StructLayout(LayoutKind.Sequential)]
public struct TOKEN_PRIVILEGES {
public int PrivilegeCount;
public long Luid;
public int Attributes;
}
public const uint TOKEN_ADJUST_PRIVILEGES = 0x0020;
public const uint TOKEN_QUERY = 0x0008;
public const int SE_PRIVILEGE_ENABLED = 0x00000002;
public const uint PROCESS_VM_READ_QUERY = 0x1010;
public static bool EnableDebugPrivilege() {
IntPtr tokenHandle;
if (!OpenProcessToken(GetCurrentProcess(),
TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, out tokenHandle))
return false;
long luid;
if (!LookupPrivilegeValue(null, "SeDebugPrivilege", out luid)) {
CloseHandle(tokenHandle);
return false;
}
TOKEN_PRIVILEGES tp = new TOKEN_PRIVILEGES();
tp.PrivilegeCount = 1;
tp.Luid = luid;
tp.Attributes = SE_PRIVILEGE_ENABLED;
bool result = AdjustTokenPrivileges(tokenHandle, false, ref tp, 0,
IntPtr.Zero, IntPtr.Zero);
CloseHandle(tokenHandle);
return result && Marshal.GetLastWin32Error() == 0;
}
public static int OpenLsass() {
Process[] procs = Process.GetProcessesByName("lsass");
if (procs.Length == 0) return -1;
int pid = procs[0].Id;
IntPtr handle = OpenProcess(PROCESS_VM_READ_QUERY, false, pid);
if (handle == IntPtr.Zero) return -2;
// Handle acquired. Sysmon EID 10 has fired.
// Close immediately; we do not read memory.
CloseHandle(handle);
return pid;
}
}
'@
$privEnabled = [LsassChokepointEmulation]::EnableDebugPrivilege()
if ($privEnabled) {
Write-Ok "SeDebugPrivilege enabled"
} else {
Write-Warn "Failed to enable SeDebugPrivilege. Handle acquisition may fail."
Write-Warn "This is expected if LSASS is running as PPL (Protected Process Light)."
}
Start-Sleep -Milliseconds 300
# ─── Stage 1: Handle Acquisition (Sysmon EID 10, ProcessAccess) ─────────────
Write-Step "Stage 1/3: Opening handle to lsass.exe (ProcessAccess telemetry)"
Write-Verbose " Targets: Sysmon EID 10 with TargetImage=lsass.exe"
Write-Verbose " This is the chokepoint invariant; every dump tool must do this"
try {
$result = [LsassChokepointEmulation]::OpenLsass()
if ($result -gt 0) {
Write-Ok "Handle opened to lsass.exe (PID $result) with GrantedAccess 0x1010"
Write-Ok "Handle closed immediately, no memory read performed"
Write-Ok "Sysmon EID 10 generated: TargetImage=lsass.exe, GrantedAccess=0x1010"
} elseif ($result -eq -1) {
Write-Warn "lsass.exe process not found (are you running on Windows?)"
} else {
$err = [System.Runtime.InteropServices.Marshal]::GetLastWin32Error()
if ($err -eq 5) {
Write-Warn "OpenProcess returned ACCESS_DENIED (error 5)"
Write-Warn "LSASS is likely running as Protected Process Light (PPL)."
Write-Warn "PPL blocks handle acquisition even with SeDebugPrivilege."
Write-Warn "To test Stage 1, either:"
Write-Warn " 1. Disable PPL: reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL /t REG_DWORD /d 0 /f (reboot required)"
Write-Warn " 2. Use a VM without PPL enabled"
Write-Warn " 3. Accept that PPL is working as intended (this IS the defense)"
Write-Warn ""
Write-Warn "Sysmon may still log the failed access attempt as EID 10."
Write-Warn "Check for GrantedAccess=0x0 or a reduced mask in your logs."
} else {
Write-Warn "OpenProcess failed (error $err)"
}
}
} catch {
Write-Warn "Handle acquisition failed: $_"
}
Start-Sleep -Milliseconds 500
# ─── Stage 2: comsvcs.dll MiniDump LOLBin (Sysmon EID 1, Process Creation) ──
Write-Step "Stage 2/3: Simulating comsvcs.dll MiniDump command line (LOLBin telemetry)"
Write-Verbose " Generates Sysmon EID 1 with CommandLine containing 'comsvcs' and 'MiniDump'"
Write-Verbose " This is the most common LOLBin technique for LSASS dumping"
# Echo the command line pattern without actually calling MiniDump
# This generates a process creation event with the suspicious command line
$lsassPid = (Get-Process lsass -ErrorAction SilentlyContinue).Id
if ($lsassPid) {
$cmdLine = "rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump $lsassPid $DumpPath full"
Write-Ok "LOLBin command pattern: $cmdLine"
# Run cmd /c echo with the suspicious command line to trigger EID 1 matching
cmd.exe /c "echo EMULATION_ONLY: $cmdLine" 2>&1 | Out-Null
Write-Ok "Sysmon EID 1 generated with comsvcs.dll MiniDump in CommandLine"
} else {
Write-Warn "lsass.exe PID not found, skipping LOLBin simulation"
}
Start-Sleep -Milliseconds 500
# ─── Stage 3: Dump File Artifact (Sysmon EID 11, File Create) ───────────────
if (-not $SkipDumpFile) {
Write-Step "Stage 3/3: Creating dump file artefact in temp directory"
Write-Verbose " Creates a marker .dmp file to trigger file creation detection"
Write-Verbose " Targets: Sysmon EID 11 with TargetFilename=*.dmp in temp path"
# Write a safe marker file (NOT a real memory dump)
$marker = "LSASS_EMULATION_MARKER | Detection Chokepoints Project | NOT A REAL DUMP"
[System.IO.File]::WriteAllText($DumpPath, $marker)
Write-Ok "Dump artefact created: $DumpPath"
Write-Ok "Sysmon EID 11 generated: .dmp file in temp directory"
} else {
Write-Warn "Stage 3 skipped (-SkipDumpFile flag set)"
}
# ─── Summary ─────────────────────────────────────────────────────────────────
Write-Host ""
Write-Step "Cleaning up artefacts"
Remove-Artefacts
Write-Host ""
Write-Host "=== Emulation Complete ===" -ForegroundColor Magenta
Write-Host ""
Write-Host "Expected detections:" -ForegroundColor White
Write-Host " [Research] Sysmon EID 10: non-system process opened handle to lsass.exe" -ForegroundColor DarkCyan
Write-Host " [Hunt] EID 10: GrantedAccess 0x1010 + CallTrace from non-AV/EDR process" -ForegroundColor DarkYellow
Write-Host " [Analyst] EID 10: 0x1010 + CallTrace + non-standard source path" -ForegroundColor DarkGreen
Write-Host ""
Write-Host "Supplementary signals (deploy as companion SIEM rules):" -ForegroundColor DarkGray
Write-Host " EID 1: comsvcs.dll MiniDump command line pattern"
Write-Host " EID 11: .dmp file created in temp directory"
Write-Host ""
Write-Host "Cleanup:" -ForegroundColor DarkGray
Write-Host " .\emulate.ps1 -CleanupOnly"
Write-Host ""
Write-Host "For higher-fidelity testing (isolated lab VM only):" -ForegroundColor DarkGray
Write-Host " 1. rundll32.exe comsvcs.dll MiniDump <lsass_pid> C:\Temp\test.dmp full"
Write-Host " 2. procdump.exe -accepteula -ma lsass.exe C:\Temp\lsass.dmp"
Write-Host " 3. These generate authentic EID 10 with dbgcore.dll in CallTrace"
Write-Host ""
@@ -0,0 +1,82 @@
title: 'LSASS Credential Dump: Non-Standard Process with Dump Mechanism and Suspicious Access Rights'
id: 2abc46f9-9c70-47cf-932e-fe803e06f5c7
status: experimental
description: >
High-fidelity detection for LSASS credential dumping. Detects a non-standard process
(outside System32 and Program Files) opening a handle to lsass.exe with credential-dump
access rights where the CallTrace reveals MiniDumpWriteDump usage (dbgcore.dll,
dbghelp.dll) or direct syscall evasion (UNKNOWN). This triple-AND (suspicious access
mask, dump mechanism fingerprint, and non-standard source path) eliminates virtually
all legitimate LSASS access. AV/EDR products run from Program Files with clean
CallTraces; attack tools run from temp paths with dbgcore.dll or UNKNOWN stacks.
A secondary selection covers handle duplication (GrantedAccess 0x0040) from non-standard
paths, the HandleKatz and nanodump evasion technique that uses NtDuplicateObject to
clone an existing LSASS handle instead of requesting a direct read handle. This
GrantedAccess value targeting lsass.exe from outside System32/Program Files has no
legitimate use case. Supplementary detections for comsvcs.dll MiniDump LOLBin
(process_creation), SSP injection (image_load), and dump file artifacts (file_event)
should be implemented as companion rules at the SIEM level for coverage across event
types. If this rule fires, assume credential compromise and begin host isolation.
references:
- https://attack.mitre.org/techniques/T1003/001/
- https://github.com/fortra/nanodump
- https://github.com/codewhitesec/HandleKatz
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
- https://www.microsoft.com/en-us/security/blog/2022/10/05/detecting-and-preventing-lsass-credential-dumping-attacks/
- https://unit42.paloaltonetworks.com/mimikatz-overview/
author: "@NovaSky0x1"
date: 2026/03/30
tags:
- attack.credential_access
- attack.t1003.001
- attack.t1003
- detection.maturity.analyst
logsource:
category: process_access
product: windows
detection:
selection_lsass_target:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|contains:
- '0x1FFFFF'
- '0x1010'
- '0x1410'
- '0x0810'
- '0x1038'
- '0x1438'
selection_dump_mechanism:
CallTrace|contains:
- 'dbgcore.dll'
- 'dbghelp.dll'
- 'UNKNOWN'
selection_nonstandard_source:
SourceImage|not|startswith:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
- 'C:\Program Files\'
- 'C:\Program Files (x86)\'
selection_handle_duplication:
TargetImage|endswith: '\lsass.exe'
GrantedAccess: '0x0040'
SourceImage|not|startswith:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
- 'C:\Program Files\'
- 'C:\Program Files (x86)\'
filter_os_core:
SourceImage|startswith:
- 'C:\Windows\System32\csrss.exe'
- 'C:\Windows\System32\lsass.exe'
- 'C:\Windows\System32\services.exe'
- 'C:\Windows\System32\svchost.exe'
- 'C:\Windows\System32\wininit.exe'
- 'C:\Windows\System32\lsaiso.exe'
- 'C:\Windows\System32\smss.exe'
- 'C:\Windows\System32\winlogon.exe'
condition: >
(selection_lsass_target and selection_dump_mechanism and selection_nonstandard_source and not filter_os_core)
or selection_handle_duplication
falsepositives:
- Portable diagnostic tools run by administrators from non-standard paths that access LSASS (should be blocked by policy in hardened environments)
- Authorized red team or penetration testing tools during sanctioned engagements
level: high
@@ -0,0 +1,94 @@
title: LSASS Access with Suspicious CallTrace or Non-Standard Source Path
id: 3d932b09-9d74-428d-bb0f-9368b28c6bb9
status: experimental
description: >
Hunt-level detection for LSASS credential dumping. Adds behavioral context to the
research baseline to separate attack tooling from legitimate security products.
CallTrace analysis reveals the mechanism used to read LSASS memory: dbgcore.dll
and dbghelp.dll indicate MiniDumpWriteDump (ProcDump, comsvcs.dll, custom dump
tools), while UNKNOWN indicates direct syscalls or ntdll unhooking. Legitimate
AV/EDR products produce clean API call stacks without these indicators. Source
path filtering captures tools staged in user-writable directories; attack tools
land in Temp, Downloads, AppData while legitimate security products run from
Program Files. This rule excludes known AV/EDR paths and WerFault to reduce the
research baseline to actionable hunt leads.
references:
- https://attack.mitre.org/techniques/T1003/001/
- https://github.com/fortra/nanodump
- https://github.com/codewhitesec/HandleKatz
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
- https://www.microsoft.com/en-us/security/blog/2022/10/05/detecting-and-preventing-lsass-credential-dumping-attacks/
author: "@NovaSky0x1"
date: 2026/03/30
tags:
- attack.credential_access
- attack.t1003.001
- attack.t1003
- detection.maturity.hunt
logsource:
category: process_access
product: windows
detection:
selection_lsass_access:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|contains:
- '0x1FFFFF'
- '0x1010'
- '0x1410'
- '0x0810'
- '0x1038'
- '0x1438'
- '0x0040'
selection_suspicious_calltrace:
CallTrace|contains:
- 'dbgcore.dll'
- 'dbghelp.dll'
- 'UNKNOWN'
selection_suspicious_source_path:
SourceImage|contains:
- '\Temp\'
- '\tmp\'
- '\Downloads\'
- '\AppData\'
- '\Users\Public\'
- '\ProgramData\'
- '\Desktop\'
- '\Recycle'
filter_os_core:
SourceImage|startswith:
- 'C:\Windows\System32\csrss.exe'
- 'C:\Windows\System32\lsass.exe'
- 'C:\Windows\System32\services.exe'
- 'C:\Windows\System32\svchost.exe'
- 'C:\Windows\System32\wininit.exe'
- 'C:\Windows\System32\lsaiso.exe'
- 'C:\Windows\System32\smss.exe'
- 'C:\Windows\System32\winlogon.exe'
filter_security_products:
SourceImage|contains:
- '\Program Files\Windows Defender\'
- '\Program Files\Microsoft Security Client\'
- '\Program Files\CrowdStrike\'
- '\Program Files\SentinelOne\'
- '\Program Files\Cylance\'
- '\Program Files\Carbon Black\'
- '\Program Files\Sophos\'
- '\Program Files\ESET\'
- '\Program Files\Kaspersky\'
- '\Program Files\Trend Micro\'
- '\Program Files (x86)\Trend Micro\'
- '\Program Files\Bitdefender\'
- '\Program Files\Malwarebytes\'
- '\Program Files\Palo Alto Networks\'
filter_werfault:
SourceImage|endswith: '\WerFault.exe'
condition: >
selection_lsass_access
and (selection_suspicious_calltrace or selection_suspicious_source_path)
and not (filter_os_core or filter_security_products or filter_werfault)
falsepositives:
- IT administrators running portable diagnostic tools from non-standard paths that inspect LSASS
- Custom monitoring agents installed outside Program Files that query process information
- Authorized penetration testing tools during sanctioned engagements
- Third-party security products not in the exclusion list (requires environment-specific tuning)
level: medium
@@ -0,0 +1,58 @@
title: LSASS Memory Access by Non-System Process (Research Baseline)
id: c08fffe8-ab3c-4e16-abd8-61e648faf95b
status: experimental
description: >
Detects any non-core-OS process opening a handle to lsass.exe with memory-read
access rights. This research-level rule establishes a baseline of all LSASS
access in the environment (AV/EDR products, WerFault, Task Manager, monitoring
tools, and actual attacks) all appear. Run this for one week to build an
environment-specific allowlist of legitimate LSASS accessors before tuning to
Hunt level. The chokepoint is invariant: every credential dumping tool (Mimikatz,
nanodump, comsvcs.dll, ProcDump, HandleKatz, direct syscall loaders) must obtain
a kernel handle to lsass.exe. Sysmon Event ID 10 captures this regardless of the
API path used.
references:
- https://attack.mitre.org/techniques/T1003/001/
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
- https://github.com/fortra/nanodump
author: "@NovaSky0x1"
date: 2026/03/30
tags:
- attack.credential_access
- attack.t1003.001
- attack.t1003
- detection.maturity.research
logsource:
category: process_access
product: windows
detection:
selection:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|contains:
- '0x1FFFFF' # PROCESS_ALL_ACCESS
- '0x1010' # PROCESS_VM_READ | PROCESS_QUERY_LIMITED_INFORMATION (Mimikatz classic)
- '0x1410' # PROCESS_VM_READ | PROCESS_QUERY_INFORMATION | PROCESS_QUERY_LIMITED_INFORMATION
- '0x0810' # PROCESS_VM_READ | PROCESS_QUERY_INFORMATION (nanodump)
- '0x1038' # PROCESS_VM_READ | PROCESS_VM_WRITE | PROCESS_VM_OPERATION
- '0x1438' # PROCESS_VM_READ | PROCESS_VM_WRITE | PROCESS_VM_OPERATION | PROCESS_QUERY_INFORMATION
- '0x0040' # PROCESS_DUP_HANDLE (handle duplication, HandleKatz, nanodump duphandle mode)
- '0x0010' # PROCESS_VM_READ alone
filter_os_core:
SourceImage|startswith:
- 'C:\Windows\System32\csrss.exe'
- 'C:\Windows\System32\lsass.exe'
- 'C:\Windows\System32\services.exe'
- 'C:\Windows\System32\svchost.exe'
- 'C:\Windows\System32\wininit.exe'
- 'C:\Windows\System32\lsaiso.exe'
- 'C:\Windows\System32\smss.exe'
- 'C:\Windows\System32\winlogon.exe'
condition: selection and not filter_os_core
falsepositives:
- Antivirus and EDR agents performing routine LSASS inspection (MsMpEng.exe, SentinelAgent.exe, CSFalconService.exe, CylanceSvc.exe)
- WerFault.exe collecting crash diagnostics for lsass.exe
- Task Manager (taskmgr.exe) when an administrator manually creates a process dump
- Performance and diagnostic tools (procexp64.exe, procmon64.exe, perfmon.exe)
- WMI provider host (wmiprvse.exe) during certain management queries
- Windows Defender Advanced Threat Protection sensor (MsSense.exe)
level: informational