mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
feat(chokepoint): add LSASS Credential Dumping (T1003.001)
New chokepoint covering the kernel-mediated handle request to lsass.exe, the invariant prerequisite for all credential dumping tools. - Chokepoint YAML with 3 stages, 24 variations, 7 evolution timeline entries - Research sigma rule: baseline all non-system LSASS access (process_access) - Hunt sigma rule: CallTrace + source path behavioral filtering - Analyst sigma rule: triple-AND (access mask + dump mechanism + non-standard path) - Emulation script with SeDebugPrivilege handling and PPL detection - 4 raw log samples, 6 OSINT pivots, CHANGELOG updated
This commit is contained in:
+13
-1
@@ -2,7 +2,19 @@
|
||||
|
||||
All notable changes to this detection chokepoints repository will be documented in this file.
|
||||
|
||||
## [2025-02-28] — LOLBAS-Style Restructuring
|
||||
## [2026-03-30] - LSASS Credential Dumping Chokepoint
|
||||
|
||||
### Added
|
||||
- `chokepoints/credential-access/lsass-credential-dumping.yml` - New chokepoint: LSASS credential dumping (T1003.001)
|
||||
- `sigma-rules/lsass-credential-dumping/research.yml` - Research-level Sigma rule (baseline all non-system LSASS access via process_access)
|
||||
- `sigma-rules/lsass-credential-dumping/hunt.yml` - Hunt-level Sigma rule (CallTrace + source path behavioral filtering)
|
||||
- `sigma-rules/lsass-credential-dumping/analyst.yml` - Analyst-level Sigma rule (triple-AND: access mask + dump mechanism + non-standard source)
|
||||
- `emulation/lsass-credential-dumping/emulate.ps1` - PowerShell emulation script with SeDebugPrivilege handling and PPL detection
|
||||
- 24 tool variations tracked (Mimikatz, comsvcs.dll, nanodump, HandleKatz, Cobalt Strike, Sliver, Havoc, Brute Ratel, Mythic, and more)
|
||||
- 4 raw log samples (EID 10 classic, EID 10 direct syscall, EID 10 handle duplication, EID 1 comsvcs LOLBin)
|
||||
- 6 OSINT pivot queries (VirusTotal, GitHub, LOLDrivers, ANY.RUN)
|
||||
|
||||
## [2025-02-28] - LOLBAS-Style Restructuring
|
||||
|
||||
### Added
|
||||
- `CONTRIBUTING.md` — full contribution guide (schema requirements, PR checklist, what not to submit)
|
||||
|
||||
@@ -0,0 +1,657 @@
|
||||
Name: LSASS Credential Dumping
|
||||
Id: c7df4fc6-05da-4a67-8dfa-efcd8e2420e2
|
||||
MitreIds:
|
||||
- T1003.001
|
||||
- T1003
|
||||
- T1547.005
|
||||
Tactics:
|
||||
- Credential Access
|
||||
Techniques:
|
||||
- 'OS Credential Dumping: LSASS Memory'
|
||||
- OS Credential Dumping
|
||||
- 'Boot or Logon Autostart Execution: Security Support Provider'
|
||||
DetectionPriority: CRITICAL
|
||||
ThreatPrevalence: VERY HIGH
|
||||
DetectionDifficulty: MEDIUM
|
||||
Description: >
|
||||
To extract plaintext credentials, NTLM hashes, or Kerberos tickets from a live
|
||||
Windows system, an attacker must read the memory of the Local Security Authority
|
||||
Subsystem Service (lsass.exe). Windows enforces process isolation at the kernel
|
||||
level: any tool that reads another process's memory must first obtain a handle via
|
||||
NtOpenProcess with appropriate access rights. This kernel-mediated handle request
|
||||
is the chokepoint; it fires regardless of whether the attacker uses Mimikatz,
|
||||
nanodump, comsvcs.dll, ProcDump, direct syscalls, or any future tool. Even
|
||||
techniques that bypass userland API hooks (ntdll unhooking, direct syscalls) still
|
||||
traverse the kernel's ObRegisterCallbacks path, which Sysmon Event ID 10
|
||||
(ProcessAccess) and ETW Threat Intelligence consume. The attacker cannot read
|
||||
lsass memory without the kernel granting the handle.
|
||||
LastUpdated: '2026-03-30'
|
||||
Author: '@NovaSky0x1'
|
||||
|
||||
Chokepoints:
|
||||
- Stage: Handle Acquisition
|
||||
Invariant: Any process must request a handle to lsass.exe with memory-read access rights from the Windows kernel.
|
||||
WhyCantBypass: >
|
||||
Windows enforces process isolation at the kernel level: NtOpenProcess must be
|
||||
called to obtain a handle, and the kernel's ObRegisterCallbacks fires for every
|
||||
handle request regardless of whether the caller used standard APIs or direct
|
||||
syscalls.
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (ProcessAccess)
|
||||
- Windows Security Event ID 4656 (Handle Requested)
|
||||
- ETW Microsoft-Windows-Threat-Intelligence (kernel-level telemetry)
|
||||
DetectionTier: Research
|
||||
SigmaRef: sigma-rules/lsass-credential-dumping/research.yml
|
||||
- Stage: Memory Read
|
||||
Invariant: The process must read lsass.exe virtual memory to extract credential material using NtReadVirtualMemory or MiniDumpWriteDump.
|
||||
WhyCantBypass: >
|
||||
Credential material (NTLM hashes, Kerberos tickets, plaintext passwords cached
|
||||
by WDigest/SSP) resides in lsass.exe process memory. There is no file or
|
||||
registry location that contains the same live credential state.
|
||||
LogSources:
|
||||
- 'Sysmon Event ID 10 (ProcessAccess: CallTrace field reveals read mechanism)'
|
||||
- 'Sysmon Event ID 11 (File Create: dump file written to disk)'
|
||||
DetectionTier: Hunt
|
||||
SigmaRef: sigma-rules/lsass-credential-dumping/hunt.yml
|
||||
BypassNote: >
|
||||
Handle duplication (NtDuplicateObject) allows an attacker to clone an existing
|
||||
handle to lsass from another process, producing GrantedAccess 0x0040 instead of
|
||||
the standard read masks. The hunt rule includes this pattern.
|
||||
- Stage: Credential Extraction
|
||||
Invariant: The attacker must parse LSASS memory structures or dump file contents to extract usable credentials, producing observable artifacts (either an in-memory read with a suspicious CallTrace, a dump file on disk, or a DLL injected into lsass via SSP).
|
||||
WhyCantBypass: >
|
||||
Credential structures in lsass memory use Microsoft's internal SSP format.
|
||||
The attacker must either parse them in-process (generating the ProcessAccess
|
||||
event) or write a dump file for offline parsing (generating a FileCreate event).
|
||||
SSP injection (loading a malicious DLL into lsass) generates an ImageLoaded
|
||||
event for a DLL outside System32.
|
||||
LogSources:
|
||||
- 'Sysmon Event ID 10 (ProcessAccess: GrantedAccess + CallTrace correlation)'
|
||||
- 'Sysmon Event ID 7 (Image Loaded: SSP DLL injection into lsass)'
|
||||
- 'Sysmon Event ID 11 (File Create: dump file artifact)'
|
||||
- 'Sysmon Event ID 1 (Process Creation: LOLBin execution)'
|
||||
DetectionTier: Analyst
|
||||
SigmaRef: sigma-rules/lsass-credential-dumping/analyst.yml
|
||||
|
||||
Variations:
|
||||
- Name: Mimikatz (sekurlsa::logonpasswords)
|
||||
FirstSeen: 2011-Q2
|
||||
Status: Active
|
||||
SourceURL: https://github.com/gentilkiwi/mimikatz
|
||||
Notes: >
|
||||
The original and most widely documented LSASS credential dumping tool. Opens
|
||||
lsass.exe with PROCESS_ALL_ACCESS (0x1FFFFF) or PROCESS_VM_READ (0x1010).
|
||||
Used by virtually every ransomware group and APT. GrantedAccess 0x1010 is the
|
||||
classic Mimikatz fingerprint.
|
||||
VariantId: mimikatz-sekurlsa
|
||||
- Name: comsvcs.dll MiniDump (LOLBin)
|
||||
FirstSeen: 2019-Q1
|
||||
Status: Active
|
||||
SourceURL: https://lolbas-project.github.io/#/OtherMSBinaries/Comsvcs
|
||||
Notes: >
|
||||
Living-off-the-land technique using rundll32.exe to call the MiniDump export
|
||||
from comsvcs.dll (a legitimate Windows DLL). Writes a full process dump of
|
||||
lsass.exe to disk. Command pattern: rundll32.exe comsvcs.dll MiniDump <pid>
|
||||
<outfile> full. The MiniDump export name is a fixed Windows API; it cannot
|
||||
be renamed without recompiling the DLL.
|
||||
VariantId: comsvcs-minidump-lolbin
|
||||
- Name: ProcDump (Sysinternals)
|
||||
FirstSeen: 2016-Q1
|
||||
Status: Active
|
||||
SourceURL: https://learn.microsoft.com/en-us/sysinternals/downloads/procdump
|
||||
Notes: >
|
||||
Microsoft Sysinternals tool used legitimately for debugging, repurposed for
|
||||
LSASS dumping. Uses MiniDumpWriteDump API (dbgcore.dll/dbghelp.dll in CallTrace).
|
||||
Signed by Microsoft, so it bypasses many application whitelisting policies.
|
||||
VariantId: procdump-sysinternals
|
||||
- Name: Nanodump
|
||||
FirstSeen: 2022-Q1
|
||||
Status: Active
|
||||
SourceURL: https://github.com/fortra/nanodump
|
||||
Notes: >
|
||||
Minimal LSASS dumper designed to evade detection. Uses direct syscalls, handle
|
||||
duplication, and process forking techniques. GrantedAccess patterns vary: 0x0810
|
||||
for direct read, 0x0040 for handle duplication mode. Produces UNKNOWN in Sysmon
|
||||
CallTrace when using direct syscalls.
|
||||
VariantId: nanodump
|
||||
- Name: HandleKatz
|
||||
FirstSeen: 2021-Q3
|
||||
Status: Active
|
||||
SourceURL: https://github.com/codewhitesec/HandleKatz
|
||||
Notes: >
|
||||
Abuses handle duplication to obtain a cloned handle to lsass.exe from another
|
||||
process that already holds one. GrantedAccess 0x0040 (PROCESS_DUP_HANDLE).
|
||||
Designed to evade detections that only look for direct PROCESS_VM_READ handles.
|
||||
VariantId: handlekatz-dup
|
||||
- Name: PPLBlade / PPLdump
|
||||
FirstSeen: 2022-Q3
|
||||
Status: Active
|
||||
SourceURL: https://github.com/tastypepperoni/PPLBlade
|
||||
Notes: >
|
||||
Bypasses Protected Process Light (PPL) protection on lsass.exe by exploiting
|
||||
vulnerable signed drivers or ELAM driver abuse. Once PPL is defeated, standard
|
||||
dump tools work. Detection shifts to the BYOVD/driver load stage (covered by
|
||||
edr-bypass-techniques) plus the subsequent LSASS access event.
|
||||
VariantId: pplblade-ppldump
|
||||
- Name: Task Manager Manual Dump
|
||||
FirstSeen: 2014-Q1
|
||||
Status: Active
|
||||
Notes: >
|
||||
Built-in Windows capability: right-click lsass.exe in Task Manager and select
|
||||
"Create dump file." Writes a full memory dump to %TEMP%. Uses 0x1FFFFF
|
||||
GrantedAccess from taskmgr.exe. Often used by less sophisticated attackers
|
||||
or during hands-on-keyboard intrusions.
|
||||
VariantId: task-manager-manual-dump
|
||||
- Name: SSP Injection (mimilib / memssp)
|
||||
FirstSeen: 2015-Q1
|
||||
Status: Active
|
||||
SourceURL: https://attack.mitre.org/techniques/T1547/005/
|
||||
Notes: >
|
||||
Injects a malicious Security Support Provider DLL into lsass.exe via
|
||||
AddSecurityPackage API or direct registry manipulation (HKLM\SYSTEM\CCS\Control\Lsa\Security Packages).
|
||||
The DLL logs all future authentication events to a file. Sysmon EID 7
|
||||
detects the DLL load from a non-System32 path.
|
||||
VariantId: ssp-injection-mimilib
|
||||
- Name: Direct Syscall Dumpers (SilentProcessExit, MirrorDump, SafetyKatz)
|
||||
FirstSeen: 2020-Q2
|
||||
Status: Active
|
||||
SourceURL: https://github.com/GhostPack/SafetyKatz
|
||||
Notes: >
|
||||
Family of tools that use direct system calls (syscall stubs) to bypass ntdll.dll
|
||||
userland hooks placed by EDR products. The kernel callback (ObRegisterCallbacks)
|
||||
still fires, so Sysmon EID 10 still generates, but the CallTrace shows UNKNOWN
|
||||
instead of ntdll.dll. MirrorDump uses DLL injection into a process with an
|
||||
existing LSASS handle.
|
||||
VariantId: direct-syscall-dumpers
|
||||
- Name: Pypykatz (Python)
|
||||
FirstSeen: 2019-Q3
|
||||
Status: Active
|
||||
SourceURL: https://github.com/skelsec/pypykatz
|
||||
Notes: >
|
||||
Pure Python implementation of Mimikatz credential extraction. Can parse LSASS
|
||||
memory dumps offline or access live LSASS via ctypes. Cross-platform, works on
|
||||
Linux for parsing dump files obtained from Windows. Overlaps with BYOSI chokepoint
|
||||
when Python interpreter is brought onto the target.
|
||||
VariantId: pypykatz-python
|
||||
- Name: Impacket secretsdump.py (Remote)
|
||||
FirstSeen: 2016-Q1
|
||||
Status: Active
|
||||
SourceURL: https://github.com/fortra/impacket
|
||||
Notes: >
|
||||
Remote credential extraction over SMB. Supports multiple modes: DCSync
|
||||
(replicating credentials via DRSUAPI), remote registry SAM/LSA dump, and
|
||||
remote LSASS memory read via svcctl service creation. When using the LSASS
|
||||
read mode, the service runs on the target and dumps locally. Overlaps with
|
||||
the remote-execution-tools chokepoint for the SMB lateral movement stage.
|
||||
VariantId: impacket-secretsdump
|
||||
- Name: CrackMapExec / NetExec (--lsa, --sam)
|
||||
FirstSeen: 2019-Q2
|
||||
Status: Active
|
||||
SourceURL: https://github.com/Pennyw0rth/NetExec
|
||||
Notes: >
|
||||
Network-based credential harvesting across multiple hosts. The --lsa and
|
||||
--sam flags dump credentials remotely via SMB service creation. The LSASS
|
||||
access event occurs on the target host, not the attacker's machine. Used
|
||||
heavily in ransomware operations for credential spraying across domains.
|
||||
VariantId: crackmapexec-netexec
|
||||
- Name: Cobalt Strike (logonpasswords, hashdump)
|
||||
FirstSeen: 2014-Q1
|
||||
Status: Active
|
||||
Notes: >
|
||||
Built-in beacon commands for credential theft. logonpasswords injects
|
||||
Mimikatz reflectively into memory; hashdump reads the SAM hive. Both
|
||||
generate Sysmon EID 10 for the LSASS access. The source process is the
|
||||
beacon's host process (often rundll32.exe or a sacrificial process),
|
||||
producing a non-standard source path in most deployments.
|
||||
VariantId: cobalt-strike-logonpasswords
|
||||
- Name: Sliver (creds, sharp-dump)
|
||||
FirstSeen: 2020-Q1
|
||||
Status: Active
|
||||
SourceURL: https://github.com/BishopFox/sliver
|
||||
Notes: >
|
||||
Open-source C2 framework from BishopFox. Supports credential dumping via
|
||||
execute-assembly (loading SharpDump or SharpKatz in-process) and through
|
||||
built-in BOF (Beacon Object File) execution. The LSASS access originates
|
||||
from the Sliver implant process, which typically runs from a user-writable
|
||||
path or injected into a legitimate process.
|
||||
VariantId: sliver-creds
|
||||
- Name: Havoc (mimikatz, coffloader)
|
||||
FirstSeen: 2022-Q3
|
||||
Status: Active
|
||||
SourceURL: https://github.com/HavocFramework/Havoc
|
||||
Notes: >
|
||||
Open-source C2 framework with built-in Mimikatz integration and COFFLoader
|
||||
for executing credential dumping BOFs. The LSASS access event comes from
|
||||
the Havoc demon process. Gaining popularity as a Cobalt Strike alternative
|
||||
in both red team and threat actor operations.
|
||||
VariantId: havoc-mimikatz
|
||||
- Name: Brute Ratel C4 (brc4, credstore)
|
||||
FirstSeen: 2022-Q1
|
||||
Status: Active
|
||||
Notes: >
|
||||
Commercial adversary simulation tool that has been adopted by ransomware
|
||||
operators (notably BlackCat/ALPHV). Includes built-in credential harvesting
|
||||
capabilities. Uses syscall-level evasion techniques similar to nanodump,
|
||||
producing UNKNOWN in Sysmon CallTrace. Leaked versions circulate in
|
||||
criminal forums.
|
||||
VariantId: brute-ratel-credstore
|
||||
- Name: Mythic (Athena, Apollo agents)
|
||||
FirstSeen: 2020-Q2
|
||||
Status: Active
|
||||
SourceURL: https://github.com/its-a-feature/Mythic
|
||||
Notes: >
|
||||
Open-source C2 platform with modular agent architecture. Credential
|
||||
dumping is implemented through agent-specific modules (Athena, Apollo)
|
||||
that call MiniDumpWriteDump or use direct syscalls. The source process
|
||||
varies by agent configuration and injection method.
|
||||
VariantId: mythic-agents
|
||||
- Name: Dumpert
|
||||
FirstSeen: 2019-Q3
|
||||
Status: Active
|
||||
SourceURL: https://github.com/outflanknl/Dumpert
|
||||
Notes: >
|
||||
One of the first public tools to use direct system calls for LSASS dumping,
|
||||
bypassing ntdll.dll API hooks. Calls NtOpenProcess and NtCreateFile via
|
||||
syscall stubs. Produces UNKNOWN in Sysmon CallTrace. Foundational technique
|
||||
adopted by nanodump and subsequent evasion tools.
|
||||
VariantId: dumpert-direct-syscall
|
||||
- Name: SharpKatz / SharpDump (.NET)
|
||||
FirstSeen: 2019-Q1
|
||||
Status: Active
|
||||
SourceURL: https://github.com/GhostPack/SharpDump
|
||||
Notes: >
|
||||
C# implementations of credential dumping designed for execute-assembly
|
||||
workflows in Cobalt Strike, Sliver, and similar frameworks. SharpKatz
|
||||
reimplements Mimikatz in .NET; SharpDump creates a minidump of LSASS.
|
||||
Both use MiniDumpWriteDump (dbgcore.dll in CallTrace) and run from
|
||||
the beacon's process context.
|
||||
VariantId: sharpkatz-sharpdump-dotnet
|
||||
- Name: Out-Minidump (PowerShell)
|
||||
FirstSeen: 2016-Q3
|
||||
Status: Declining
|
||||
SourceURL: https://github.com/PowerShellMafia/PowerSploit
|
||||
Notes: >
|
||||
PowerShell-based LSASS dump using .NET P/Invoke to call MiniDumpWriteDump.
|
||||
Part of the PowerSploit toolkit. Generates both a PowerShell script block
|
||||
log and Sysmon EID 10. Less common now due to AMSI and Script Block Logging
|
||||
making PowerShell-based attacks more visible.
|
||||
VariantId: out-minidump-powershell
|
||||
- Name: LSASS Shtinkering (Process Snapshotting)
|
||||
FirstSeen: 2022-Q1
|
||||
Status: Emerging
|
||||
SourceURL: https://github.com/deepinstinct/Lsass-Shtinkering
|
||||
Notes: >
|
||||
Uses PssNtCaptureSnapshot to create a snapshot of the LSASS process, then
|
||||
reads credentials from the snapshot instead of live memory. The snapshot
|
||||
API still requires a handle to lsass.exe, so Sysmon EID 10 fires, but
|
||||
the GrantedAccess mask may differ from standard dump patterns. Some EDR
|
||||
products do not monitor snapshot operations.
|
||||
VariantId: lsass-shtinkering-snapshot
|
||||
- Name: Skeleton Key (SSP Backdoor)
|
||||
FirstSeen: 2015-Q1
|
||||
Status: Active
|
||||
SourceURL: https://attack.mitre.org/software/S0007/
|
||||
Notes: >
|
||||
Variant of SSP injection that patches the LSASS authentication flow to
|
||||
accept a universal "skeleton key" password for any domain account. Unlike
|
||||
mimilib which logs credentials, Skeleton Key modifies authentication
|
||||
in-memory. Detected via Sysmon EID 7 (DLL loaded into lsass from
|
||||
non-System32 path) and anomalous Kerberos authentication patterns.
|
||||
VariantId: skeleton-key-ssp
|
||||
- Name: LaZagne
|
||||
FirstSeen: 2015-Q1
|
||||
Status: Active
|
||||
SourceURL: https://github.com/AlessandroZ/LaZagne
|
||||
Notes: >
|
||||
Multi-platform credential harvester that extracts passwords from browsers,
|
||||
databases, mail clients, Wi-Fi, and LSASS. Uses ctypes on Windows to call
|
||||
OpenProcess against lsass.exe. Cross-platform (Python), often deployed
|
||||
alongside BYOSI techniques.
|
||||
VariantId: lazagne-multi-platform
|
||||
- Name: EDRSandBlast (LSASS dump mode)
|
||||
FirstSeen: 2022-Q4
|
||||
Status: Active
|
||||
SourceURL: https://github.com/wavestone-cdt/EDRSandblast
|
||||
Notes: >
|
||||
Combines BYOVD driver exploitation with LSASS credential dumping in a
|
||||
single tool. Loads a vulnerable driver to blind EDR kernel callbacks, then
|
||||
dumps LSASS. The driver load is detectable via Sysmon EID 6 (see
|
||||
edr-bypass-techniques); the LSASS access still generates EID 10 if Sysmon
|
||||
kernel callbacks survive the patching attempt.
|
||||
VariantId: edrsandblast-lsass
|
||||
|
||||
Prerequisites:
|
||||
- The attacker must have local administrator or SYSTEM privileges on the target host (LSASS access requires SeDebugPrivilege or equivalent)
|
||||
- LSASS must not be running as a Protected Process Light (PPL), or the attacker must first bypass PPL (see edr-bypass-techniques)
|
||||
- Credential Guard (VBS) must not be active, or the attacker must compromise the isolated LSA environment (significantly harder, no known public tools)
|
||||
- Sysmon or equivalent kernel-level telemetry must be deployed for chokepoint visibility (Security EID 4656 provides partial coverage without Sysmon)
|
||||
|
||||
EvolutionTimeline:
|
||||
- Date: 2011-Q2
|
||||
Event: Mimikatz released by Benjamin Delpy
|
||||
Change: >
|
||||
First publicly available tool for extracting plaintext credentials from LSASS
|
||||
memory. Used PROCESS_ALL_ACCESS (0x1FFFFF) handle with standard Windows API
|
||||
calls through ntdll.dll.
|
||||
DetectionImpact: >
|
||||
No detection existed. LSASS memory access was not monitored by any standard
|
||||
Windows audit configuration. Security products relied on signature-based
|
||||
detection of the Mimikatz binary itself.
|
||||
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2016-Q1
|
||||
Event: 'LOLBin techniques emerge: ProcDump and comsvcs.dll repurposed for LSASS dumping'
|
||||
Change: >
|
||||
Attackers shifted from custom tools to Microsoft-signed binaries (procdump.exe,
|
||||
rundll32.exe + comsvcs.dll) to bypass application whitelisting and signature
|
||||
detection. The dump is written to disk for offline parsing.
|
||||
DetectionImpact: >
|
||||
Binary signature detection bypassed completely. Detection shifted to process
|
||||
creation monitoring for known LOLBin command patterns and file creation events
|
||||
for .dmp files in temp directories.
|
||||
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2019-Q2
|
||||
Event: Sysmon EID 10 (ProcessAccess) adopted as primary LSASS monitoring source
|
||||
Change: >
|
||||
Microsoft Sysinternals added ProcessAccess logging to Sysmon, providing
|
||||
kernel-level visibility into handle requests targeting lsass.exe. The
|
||||
GrantedAccess and CallTrace fields became the foundation for behavioral
|
||||
LSASS access detection independent of specific tool signatures.
|
||||
DetectionImpact: >
|
||||
Transformed LSASS monitoring from signature-based to behavior-based. Defenders
|
||||
could now detect any tool accessing LSASS by its access mask and calling
|
||||
mechanism rather than its binary name or hash.
|
||||
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2020-Q2
|
||||
Event: Direct syscall and ntdll unhooking techniques proliferate
|
||||
Change: >
|
||||
Tools like SilentProcessExit, MirrorDump, and custom loaders bypass EDR
|
||||
userland hooks by making system calls directly to the kernel, skipping
|
||||
ntdll.dll entirely. This produces UNKNOWN in Sysmon CallTrace instead of
|
||||
the standard ntdll.dll entry.
|
||||
DetectionImpact: >
|
||||
EDR products relying on ntdll.dll API hooks lost visibility. Sysmon EID 10
|
||||
still fires because the kernel ObRegisterCallbacks mechanism operates below
|
||||
the userland hook layer. UNKNOWN in CallTrace became a detection signal
|
||||
rather than a blind spot.
|
||||
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2021-Q3
|
||||
Event: Handle duplication evasion (HandleKatz, nanodump duphandle mode)
|
||||
Change: >
|
||||
Instead of directly opening lsass.exe, these tools open a different process
|
||||
that already holds a handle to lsass, then duplicate that handle via
|
||||
NtDuplicateObject. This produces GrantedAccess 0x0040 (PROCESS_DUP_HANDLE)
|
||||
rather than the expected 0x1010 or 0x1FFFFF.
|
||||
DetectionImpact: >
|
||||
Detection rules looking only for PROCESS_VM_READ or PROCESS_ALL_ACCESS missed
|
||||
the duplication pattern. Rules updated to include 0x0040 as a suspicious
|
||||
GrantedAccess value when targeting lsass.exe from a non-standard source path.
|
||||
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2022-Q3
|
||||
Event: PPL bypass tools combine BYOVD with LSASS dumping
|
||||
Change: >
|
||||
PPLBlade, PPLdump, and similar tools load a vulnerable signed kernel driver
|
||||
to disable Protected Process Light on lsass.exe before performing the dump.
|
||||
Two-stage attack: driver load (EID 6) precedes LSASS access (EID 10).
|
||||
DetectionImpact: >
|
||||
PPL protection is defeated before the dump occurs, so the LSASS access event
|
||||
appears normal from an access-rights perspective. Detection requires
|
||||
correlating the vulnerable driver load with subsequent LSASS access. See
|
||||
edr-bypass-techniques for the driver load stage.
|
||||
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
|
||||
Variants: []
|
||||
EventType: event
|
||||
- Date: 2024-Q3
|
||||
Event: LSASS credential dumping remains universal across ransomware groups
|
||||
Change: >
|
||||
Kaspersky, Mandiant, and Cisco Talos reports confirm T1003.001 in 5 of 5
|
||||
major ransomware families (BlackBasta, BlackCat, Akira, Qilin, LockBit).
|
||||
Tool choice varies (Mimikatz, comsvcs.dll, nanodump, custom tools) but
|
||||
the LSASS access event is present in every case.
|
||||
DetectionImpact: >
|
||||
No new evasion of the kernel-level chokepoint. Tool diversity increased but
|
||||
behavioral detection via Sysmon EID 10 remained effective across all variants.
|
||||
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
|
||||
Variants: []
|
||||
EventType: event
|
||||
|
||||
EmulationScript:
|
||||
File: emulation/lsass-credential-dumping/emulate.ps1
|
||||
Language: powershell
|
||||
AtomicRef: T1003.001
|
||||
Description: Simulates LSASS credential dumping chokepoint stages for detection validation
|
||||
SafetyNotes: >
|
||||
Run in an isolated lab VM with Sysmon deployed. Requires Administrator privileges.
|
||||
Does NOT extract credentials. Opens and immediately closes a handle to lsass.exe
|
||||
to generate EID 10 telemetry, simulates comsvcs.dll command line for EID 1, and
|
||||
creates a marker .dmp file for EID 11.
|
||||
|
||||
Detections:
|
||||
- Level: Research
|
||||
Description: Baseline all non-system processes accessing lsass.exe with memory-read permissions
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (ProcessAccess)
|
||||
Logic: >
|
||||
Monitor ProcessAccess events where TargetImage is lsass.exe and GrantedAccess
|
||||
includes memory-read flags (0x1010, 0x1FFFFF, 0x1410, 0x0810, 0x0040, 0x1038,
|
||||
0x1438, 0x0010). Filter only core OS processes (csrss.exe, services.exe,
|
||||
svchost.exe, lsass.exe self-access, lsaiso.exe, wininit.exe, smss.exe,
|
||||
winlogon.exe). Everything else, including AV/EDR products, WerFault,
|
||||
and Task Manager, appears in this baseline. Run for one week to establish the
|
||||
environment-specific set of legitimate LSASS accessors before tuning.
|
||||
ExpectedFPRate: High
|
||||
UseCase: >
|
||||
Detection engineers baselining LSASS access patterns in a new environment.
|
||||
Identifies which processes normally touch LSASS to build the environment-specific
|
||||
allowlist needed for Hunt and Analyst rules.
|
||||
SigmaRule: sigma-rules/lsass-credential-dumping/research.yml
|
||||
|
||||
- Level: Hunt
|
||||
Description: LSASS access with suspicious CallTrace, non-standard source path, or LOLBin dump pattern
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (ProcessAccess)
|
||||
- Sysmon Event ID 1 (Process Creation)
|
||||
Logic: >
|
||||
ProcessAccess to lsass.exe with credential-dump access masks WHERE (A) CallTrace
|
||||
contains dbgcore.dll or dbghelp.dll (MiniDumpWriteDump, used by comsvcs.dll,
|
||||
ProcDump, Out-Minidump) or UNKNOWN (direct syscall / ntdll unhooking), OR (B)
|
||||
SourceImage is in a user-writable path (Temp, Downloads, AppData, ProgramData,
|
||||
Users\Public), OR (C) Process creation matches LOLBin patterns (rundll32 +
|
||||
comsvcs + MiniDump, or procdump targeting lsass). Excludes core OS processes,
|
||||
known AV/EDR paths (Program Files\Windows Defender, CrowdStrike, SentinelOne,
|
||||
Sophos, etc.), and WerFault.
|
||||
ExpectedFPRate: Medium
|
||||
UseCase: >
|
||||
Active threat hunting for credential dumping. Periodic sweeps during incident
|
||||
response or campaign investigations. CallTrace analysis separates legitimate
|
||||
security product access from dump tooling behavior.
|
||||
SigmaRule: sigma-rules/lsass-credential-dumping/hunt.yml
|
||||
|
||||
- Level: Analyst
|
||||
Description: Non-standard process accessing LSASS with dump mechanism fingerprint and credential-dump access rights
|
||||
LogSources:
|
||||
- Sysmon Event ID 10 (ProcessAccess)
|
||||
Logic: >
|
||||
ProcessAccess to lsass.exe with credential-dump access mask (0x1FFFFF,
|
||||
0x1010, 0x1410, 0x0810, 0x1038, 0x1438) AND CallTrace shows
|
||||
MiniDumpWriteDump (dbgcore.dll, dbghelp.dll) or direct syscall (UNKNOWN)
|
||||
AND source process is outside System32 and Program Files. This triple-AND
|
||||
eliminates virtually all legitimate LSASS access; AV/EDR runs from Program
|
||||
Files with clean CallTraces. A secondary selection covers handle duplication
|
||||
(GrantedAccess 0x0040) targeting lsass from non-standard paths, catching the
|
||||
HandleKatz and nanodump duphandle evasion technique. Supplementary detections
|
||||
for comsvcs.dll MiniDump LOLBin (process_creation), SSP injection
|
||||
(image_load), and dump file artifacts (file_event) should be deployed as
|
||||
companion SIEM rules for additional coverage across event types.
|
||||
ExpectedFPRate: Low
|
||||
UseCase: >
|
||||
Automated SOC alerting. Direct escalation to Tier 2/IR. If this fires,
|
||||
assume credential compromise and begin containment (isolate host, reset
|
||||
exposed credentials, check for lateral movement via pass-the-hash).
|
||||
SigmaRule: sigma-rules/lsass-credential-dumping/analyst.yml
|
||||
|
||||
Intel:
|
||||
- Name: 'MITRE ATT&CK: T1003.001, OS Credential Dumping: LSASS Memory'
|
||||
Tier: primary
|
||||
URL: https://attack.mitre.org/techniques/T1003/001/
|
||||
Description: >
|
||||
Primary technique definition. Documents real-world procedures by Mimikatz,
|
||||
ProcDump, Windows Task Manager, and comsvcs.dll. Lists mitigations including
|
||||
Credential Guard and PPL.
|
||||
- Name: 'Microsoft: Credential Guard Overview'
|
||||
Tier: supporting
|
||||
URL: https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/
|
||||
Description: >
|
||||
Microsoft's documentation on Credential Guard (Virtualization Based Security).
|
||||
When deployed, isolates LSASS credential material into a separate virtual
|
||||
machine, preventing direct memory read attacks entirely. The chokepoint
|
||||
detection remains relevant for environments without Credential Guard.
|
||||
- Name: 'Sysmon: Event ID 10 ProcessAccess'
|
||||
Tier: supporting
|
||||
URL: https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
|
||||
Description: >
|
||||
Sysmon documentation covering ProcessAccess event generation. Critical for
|
||||
understanding GrantedAccess masks, CallTrace format, and configuration
|
||||
requirements for LSASS monitoring.
|
||||
- Name: 'Fortra: Nanodump'
|
||||
Tier: supporting
|
||||
URL: https://github.com/fortra/nanodump
|
||||
Description: >
|
||||
Source code for nanodump, a minimal LSASS dumper demonstrating direct syscall,
|
||||
handle duplication, and process forking evasion techniques. Essential reference
|
||||
for understanding modern credential dump evasion and why GrantedAccess 0x0040
|
||||
and UNKNOWN CallTrace patterns must be included in detection rules.
|
||||
|
||||
RelatedChokepoints:
|
||||
- browser-credential-theft
|
||||
- edr-bypass-techniques
|
||||
- remote-execution-tools
|
||||
|
||||
OsintSources:
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: 'behavior_processes:"lsass" behavior:"NtOpenProcess" tag:cred-stealer'
|
||||
Notes: >
|
||||
Finds malware samples that access lsass.exe during sandbox execution. Pivot
|
||||
to the behavior tab to extract GrantedAccess patterns and dump methodology
|
||||
used by each sample. Cross-reference with CallTrace values to identify
|
||||
new evasion techniques.
|
||||
- Platform: VirusTotal Intelligence
|
||||
Query: 'content:"sekurlsa" OR content:"MiniDumpWriteDump" OR content:"comsvcs" positives:5+'
|
||||
Notes: >
|
||||
Finds samples containing known credential dump strings. Useful for tracking
|
||||
new Mimikatz variants, custom dump tools, and LOLBin abuse scripts that
|
||||
reference comsvcs.dll MiniDump.
|
||||
- Platform: GitHub Code Search
|
||||
Query: '"NtOpenProcess" "lsass" language:C OR language:C++'
|
||||
Notes: >
|
||||
Finds new credential dumping tool source code. Monitor for novel evasion
|
||||
techniques: direct syscall wrappers, handle duplication implementations,
|
||||
and process forking methods that may require detection rule updates.
|
||||
- Platform: GitHub Code Search
|
||||
Query: '"MiniDumpWriteDump" "lsass" OR "sekurlsa" language:C#'
|
||||
Notes: >
|
||||
Finds .NET-based credential dump tools (SharpKatz, SafetyKatz, SharpDump).
|
||||
These generate dbgcore.dll in CallTrace, confirming analyst rule coverage.
|
||||
- Platform: LOLDrivers
|
||||
Query: https://www.loldrivers.io/
|
||||
Notes: >
|
||||
Database of known vulnerable kernel drivers used for BYOVD attacks. PPL
|
||||
bypass tools (PPLBlade, PPLdump) require loading a vulnerable driver before
|
||||
dumping LSASS. Cross-reference with edr-bypass-techniques chokepoint for
|
||||
driver load detection coverage.
|
||||
- Platform: ANY.RUN
|
||||
Query: 'suricata:"lsass" OR commandline:"sekurlsa" OR commandline:"comsvcs"'
|
||||
Notes: >
|
||||
Sandbox search for samples that interact with lsass.exe during execution.
|
||||
ANY.RUN provides process tree visualization showing the parent-child chain
|
||||
and GrantedAccess values, useful for building detection rule context.
|
||||
|
||||
References:
|
||||
- https://attack.mitre.org/techniques/T1003/001/
|
||||
- https://attack.mitre.org/techniques/T1003/
|
||||
- https://github.com/fortra/nanodump
|
||||
- https://github.com/codewhitesec/HandleKatz
|
||||
- https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/
|
||||
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
|
||||
- https://www.blackhillsinfosec.com/red-teamers-cookbook-byoi-bring-your-own-interpreter/
|
||||
|
||||
RawLogs:
|
||||
- Source: Microsoft-Windows-Sysmon/Operational
|
||||
EventId: 10
|
||||
Description: 'Mimikatz-style LSASS handle acquisition: classic 0x1010 access mask from user-writable path'
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Hunt
|
||||
- Analyst
|
||||
Sample: >
|
||||
EventID: 10 (ProcessAccess)
|
||||
UtcTime: 2025-11-14 02:31:18.442
|
||||
SourceProcessGUID: {a1b2c3d4-5e6f-7890-abcd-ef0123456789}
|
||||
SourceProcessId: 7284
|
||||
SourceImage: C:\Users\jsmith\AppData\Local\Temp\procdump64.exe
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
TargetProcessId: 672
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
GrantedAccess: 0x1010
|
||||
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\Windows\SYSTEM32\dbgcore.dll+6350|C:\Users\jsmith\AppData\Local\Temp\procdump64.exe+1f234
|
||||
- Source: Microsoft-Windows-Sysmon/Operational
|
||||
EventId: 10
|
||||
Description: 'Direct syscall LSASS access: UNKNOWN in CallTrace indicates ntdll hook bypass'
|
||||
MatchedRules:
|
||||
- Research
|
||||
- Hunt
|
||||
- Analyst
|
||||
Sample: >
|
||||
EventID: 10 (ProcessAccess)
|
||||
UtcTime: 2025-11-14 02:44:07.891
|
||||
SourceProcessGUID: {a1b2c3d4-9a8b-7c6d-5e4f-3a2b1c0d9e8f}
|
||||
SourceProcessId: 3412
|
||||
SourceImage: C:\Users\jsmith\Downloads\update.exe
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
TargetProcessId: 672
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
GrantedAccess: 0x1FFFFF
|
||||
CallTrace: UNKNOWN
|
||||
- Source: Microsoft-Windows-Sysmon/Operational
|
||||
EventId: 10
|
||||
Description: 'Handle duplication targeting LSASS: HandleKatz/nanodump evasion with GrantedAccess 0x0040'
|
||||
MatchedRules:
|
||||
- Analyst
|
||||
Sample: >
|
||||
EventID: 10 (ProcessAccess)
|
||||
UtcTime: 2025-11-14 03:02:55.103
|
||||
SourceProcessGUID: {a1b2c3d4-1122-3344-5566-778899aabbcc}
|
||||
SourceProcessId: 5890
|
||||
SourceImage: C:\ProgramData\staging\svcloader.exe
|
||||
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
|
||||
TargetProcessId: 672
|
||||
TargetImage: C:\Windows\System32\lsass.exe
|
||||
GrantedAccess: 0x0040
|
||||
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\ProgramData\staging\svcloader.exe+a238
|
||||
- Source: Microsoft-Windows-Sysmon/Operational
|
||||
EventId: 1
|
||||
Description: 'comsvcs.dll MiniDump LOLBin: rundll32 invoking MiniDump export for LSASS dump'
|
||||
MatchedRules:
|
||||
- Hunt
|
||||
Sample: >
|
||||
EventID: 1 (Process Create)
|
||||
UtcTime: 2025-11-14 03:15:22.667
|
||||
ProcessGUID: {a1b2c3d4-aabb-ccdd-eeff-001122334455}
|
||||
ProcessId: 8844
|
||||
Image: C:\Windows\System32\rundll32.exe
|
||||
CommandLine: rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
|
||||
ParentProcessGUID: {a1b2c3d4-5566-7788-99aa-bbccddeeff00}
|
||||
ParentProcessId: 4120
|
||||
ParentImage: C:\Windows\System32\cmd.exe
|
||||
ParentCommandLine: cmd.exe /c rundll32.exe comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
|
||||
|
||||
TheConstant: A process must open a kernel-mediated handle to lsass.exe and read its virtual memory to extract credential material
|
||||
@@ -0,0 +1,240 @@
|
||||
#Requires -Version 5.1
|
||||
#Requires -RunAsAdministrator
|
||||
# MITRE ATT&CK: T1003.001, OS Credential Dumping: LSASS Memory
|
||||
# Simulates LSASS credential dumping chokepoint stages: handle acquisition, memory read, and dump artifact.
|
||||
# Does NOT extract credentials; uses safe API calls to generate detection telemetry only.
|
||||
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[switch]$SkipDumpFile,
|
||||
[switch]$CleanupOnly,
|
||||
[string]$DumpPath = (Join-Path $env:TEMP "lsass_emu_$(Get-Random).dmp")
|
||||
)
|
||||
|
||||
Set-StrictMode -Version Latest
|
||||
$ErrorActionPreference = 'Continue'
|
||||
|
||||
function Write-Step ([string]$Msg) { Write-Host "[*] $Msg" -ForegroundColor Cyan }
|
||||
function Write-Ok ([string]$Msg) { Write-Host "[+] $Msg" -ForegroundColor Green }
|
||||
function Write-Warn ([string]$Msg) { Write-Host "[!] $Msg" -ForegroundColor Yellow }
|
||||
|
||||
function Remove-Artefacts {
|
||||
if (Test-Path $DumpPath) {
|
||||
Remove-Item -Path $DumpPath -Force -ErrorAction SilentlyContinue
|
||||
Write-Ok "Removed dump artefact: $DumpPath"
|
||||
} else {
|
||||
Write-Warn "No artefacts found at $DumpPath"
|
||||
}
|
||||
}
|
||||
|
||||
if ($CleanupOnly) { Remove-Artefacts; exit 0 }
|
||||
|
||||
Write-Host ""
|
||||
Write-Host "=== LSASS Credential Dumping Emulation ===" -ForegroundColor Magenta
|
||||
Write-Host " T1003.001 | Detection Chokepoints Project" -ForegroundColor DarkGray
|
||||
Write-Host ""
|
||||
Write-Warn "This script generates detection telemetry ONLY."
|
||||
Write-Warn "No credentials are extracted. No memory is parsed."
|
||||
Write-Warn "Requires Administrator privileges for SeDebugPrivilege."
|
||||
Write-Host ""
|
||||
|
||||
# ─── Enable SeDebugPrivilege ────────────────────────────────────────────────
|
||||
|
||||
Write-Step "Enabling SeDebugPrivilege (required for LSASS handle access)"
|
||||
|
||||
Add-Type -TypeDefinition @'
|
||||
using System;
|
||||
using System.Diagnostics;
|
||||
using System.Runtime.InteropServices;
|
||||
|
||||
public class LsassChokepointEmulation {
|
||||
[DllImport("kernel32.dll", SetLastError = true)]
|
||||
public static extern IntPtr OpenProcess(
|
||||
uint dwDesiredAccess, bool bInheritHandle, int dwProcessId);
|
||||
|
||||
[DllImport("kernel32.dll", SetLastError = true)]
|
||||
[return: MarshalAs(UnmanagedType.Bool)]
|
||||
public static extern bool CloseHandle(IntPtr hObject);
|
||||
|
||||
[DllImport("advapi32.dll", SetLastError = true)]
|
||||
[return: MarshalAs(UnmanagedType.Bool)]
|
||||
public static extern bool OpenProcessToken(
|
||||
IntPtr ProcessHandle, uint DesiredAccess, out IntPtr TokenHandle);
|
||||
|
||||
[DllImport("advapi32.dll", SetLastError = true, CharSet = CharSet.Auto)]
|
||||
[return: MarshalAs(UnmanagedType.Bool)]
|
||||
public static extern bool LookupPrivilegeValue(
|
||||
string lpSystemName, string lpName, out long lpLuid);
|
||||
|
||||
[DllImport("advapi32.dll", SetLastError = true)]
|
||||
[return: MarshalAs(UnmanagedType.Bool)]
|
||||
public static extern bool AdjustTokenPrivileges(
|
||||
IntPtr TokenHandle, bool DisableAllPrivileges,
|
||||
ref TOKEN_PRIVILEGES NewState, int BufferLength,
|
||||
IntPtr PreviousState, IntPtr ReturnLength);
|
||||
|
||||
[DllImport("kernel32.dll")]
|
||||
public static extern IntPtr GetCurrentProcess();
|
||||
|
||||
[StructLayout(LayoutKind.Sequential)]
|
||||
public struct TOKEN_PRIVILEGES {
|
||||
public int PrivilegeCount;
|
||||
public long Luid;
|
||||
public int Attributes;
|
||||
}
|
||||
|
||||
public const uint TOKEN_ADJUST_PRIVILEGES = 0x0020;
|
||||
public const uint TOKEN_QUERY = 0x0008;
|
||||
public const int SE_PRIVILEGE_ENABLED = 0x00000002;
|
||||
public const uint PROCESS_VM_READ_QUERY = 0x1010;
|
||||
|
||||
public static bool EnableDebugPrivilege() {
|
||||
IntPtr tokenHandle;
|
||||
if (!OpenProcessToken(GetCurrentProcess(),
|
||||
TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, out tokenHandle))
|
||||
return false;
|
||||
|
||||
long luid;
|
||||
if (!LookupPrivilegeValue(null, "SeDebugPrivilege", out luid)) {
|
||||
CloseHandle(tokenHandle);
|
||||
return false;
|
||||
}
|
||||
|
||||
TOKEN_PRIVILEGES tp = new TOKEN_PRIVILEGES();
|
||||
tp.PrivilegeCount = 1;
|
||||
tp.Luid = luid;
|
||||
tp.Attributes = SE_PRIVILEGE_ENABLED;
|
||||
|
||||
bool result = AdjustTokenPrivileges(tokenHandle, false, ref tp, 0,
|
||||
IntPtr.Zero, IntPtr.Zero);
|
||||
CloseHandle(tokenHandle);
|
||||
return result && Marshal.GetLastWin32Error() == 0;
|
||||
}
|
||||
|
||||
public static int OpenLsass() {
|
||||
Process[] procs = Process.GetProcessesByName("lsass");
|
||||
if (procs.Length == 0) return -1;
|
||||
|
||||
int pid = procs[0].Id;
|
||||
IntPtr handle = OpenProcess(PROCESS_VM_READ_QUERY, false, pid);
|
||||
|
||||
if (handle == IntPtr.Zero) return -2;
|
||||
|
||||
// Handle acquired. Sysmon EID 10 has fired.
|
||||
// Close immediately; we do not read memory.
|
||||
CloseHandle(handle);
|
||||
return pid;
|
||||
}
|
||||
}
|
||||
'@
|
||||
|
||||
$privEnabled = [LsassChokepointEmulation]::EnableDebugPrivilege()
|
||||
if ($privEnabled) {
|
||||
Write-Ok "SeDebugPrivilege enabled"
|
||||
} else {
|
||||
Write-Warn "Failed to enable SeDebugPrivilege. Handle acquisition may fail."
|
||||
Write-Warn "This is expected if LSASS is running as PPL (Protected Process Light)."
|
||||
}
|
||||
|
||||
Start-Sleep -Milliseconds 300
|
||||
|
||||
# ─── Stage 1: Handle Acquisition (Sysmon EID 10, ProcessAccess) ─────────────
|
||||
|
||||
Write-Step "Stage 1/3: Opening handle to lsass.exe (ProcessAccess telemetry)"
|
||||
Write-Verbose " Targets: Sysmon EID 10 with TargetImage=lsass.exe"
|
||||
Write-Verbose " This is the chokepoint invariant; every dump tool must do this"
|
||||
|
||||
try {
|
||||
$result = [LsassChokepointEmulation]::OpenLsass()
|
||||
if ($result -gt 0) {
|
||||
Write-Ok "Handle opened to lsass.exe (PID $result) with GrantedAccess 0x1010"
|
||||
Write-Ok "Handle closed immediately, no memory read performed"
|
||||
Write-Ok "Sysmon EID 10 generated: TargetImage=lsass.exe, GrantedAccess=0x1010"
|
||||
} elseif ($result -eq -1) {
|
||||
Write-Warn "lsass.exe process not found (are you running on Windows?)"
|
||||
} else {
|
||||
$err = [System.Runtime.InteropServices.Marshal]::GetLastWin32Error()
|
||||
if ($err -eq 5) {
|
||||
Write-Warn "OpenProcess returned ACCESS_DENIED (error 5)"
|
||||
Write-Warn "LSASS is likely running as Protected Process Light (PPL)."
|
||||
Write-Warn "PPL blocks handle acquisition even with SeDebugPrivilege."
|
||||
Write-Warn "To test Stage 1, either:"
|
||||
Write-Warn " 1. Disable PPL: reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL /t REG_DWORD /d 0 /f (reboot required)"
|
||||
Write-Warn " 2. Use a VM without PPL enabled"
|
||||
Write-Warn " 3. Accept that PPL is working as intended (this IS the defense)"
|
||||
Write-Warn ""
|
||||
Write-Warn "Sysmon may still log the failed access attempt as EID 10."
|
||||
Write-Warn "Check for GrantedAccess=0x0 or a reduced mask in your logs."
|
||||
} else {
|
||||
Write-Warn "OpenProcess failed (error $err)"
|
||||
}
|
||||
}
|
||||
} catch {
|
||||
Write-Warn "Handle acquisition failed: $_"
|
||||
}
|
||||
|
||||
Start-Sleep -Milliseconds 500
|
||||
|
||||
# ─── Stage 2: comsvcs.dll MiniDump LOLBin (Sysmon EID 1, Process Creation) ──
|
||||
|
||||
Write-Step "Stage 2/3: Simulating comsvcs.dll MiniDump command line (LOLBin telemetry)"
|
||||
Write-Verbose " Generates Sysmon EID 1 with CommandLine containing 'comsvcs' and 'MiniDump'"
|
||||
Write-Verbose " This is the most common LOLBin technique for LSASS dumping"
|
||||
|
||||
# Echo the command line pattern without actually calling MiniDump
|
||||
# This generates a process creation event with the suspicious command line
|
||||
$lsassPid = (Get-Process lsass -ErrorAction SilentlyContinue).Id
|
||||
if ($lsassPid) {
|
||||
$cmdLine = "rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump $lsassPid $DumpPath full"
|
||||
Write-Ok "LOLBin command pattern: $cmdLine"
|
||||
# Run cmd /c echo with the suspicious command line to trigger EID 1 matching
|
||||
cmd.exe /c "echo EMULATION_ONLY: $cmdLine" 2>&1 | Out-Null
|
||||
Write-Ok "Sysmon EID 1 generated with comsvcs.dll MiniDump in CommandLine"
|
||||
} else {
|
||||
Write-Warn "lsass.exe PID not found, skipping LOLBin simulation"
|
||||
}
|
||||
|
||||
Start-Sleep -Milliseconds 500
|
||||
|
||||
# ─── Stage 3: Dump File Artifact (Sysmon EID 11, File Create) ───────────────
|
||||
|
||||
if (-not $SkipDumpFile) {
|
||||
Write-Step "Stage 3/3: Creating dump file artefact in temp directory"
|
||||
Write-Verbose " Creates a marker .dmp file to trigger file creation detection"
|
||||
Write-Verbose " Targets: Sysmon EID 11 with TargetFilename=*.dmp in temp path"
|
||||
|
||||
# Write a safe marker file (NOT a real memory dump)
|
||||
$marker = "LSASS_EMULATION_MARKER | Detection Chokepoints Project | NOT A REAL DUMP"
|
||||
[System.IO.File]::WriteAllText($DumpPath, $marker)
|
||||
Write-Ok "Dump artefact created: $DumpPath"
|
||||
Write-Ok "Sysmon EID 11 generated: .dmp file in temp directory"
|
||||
} else {
|
||||
Write-Warn "Stage 3 skipped (-SkipDumpFile flag set)"
|
||||
}
|
||||
|
||||
# ─── Summary ─────────────────────────────────────────────────────────────────
|
||||
|
||||
Write-Host ""
|
||||
Write-Step "Cleaning up artefacts"
|
||||
Remove-Artefacts
|
||||
|
||||
Write-Host ""
|
||||
Write-Host "=== Emulation Complete ===" -ForegroundColor Magenta
|
||||
Write-Host ""
|
||||
Write-Host "Expected detections:" -ForegroundColor White
|
||||
Write-Host " [Research] Sysmon EID 10: non-system process opened handle to lsass.exe" -ForegroundColor DarkCyan
|
||||
Write-Host " [Hunt] EID 10: GrantedAccess 0x1010 + CallTrace from non-AV/EDR process" -ForegroundColor DarkYellow
|
||||
Write-Host " [Analyst] EID 10: 0x1010 + CallTrace + non-standard source path" -ForegroundColor DarkGreen
|
||||
Write-Host ""
|
||||
Write-Host "Supplementary signals (deploy as companion SIEM rules):" -ForegroundColor DarkGray
|
||||
Write-Host " EID 1: comsvcs.dll MiniDump command line pattern"
|
||||
Write-Host " EID 11: .dmp file created in temp directory"
|
||||
Write-Host ""
|
||||
Write-Host "Cleanup:" -ForegroundColor DarkGray
|
||||
Write-Host " .\emulate.ps1 -CleanupOnly"
|
||||
Write-Host ""
|
||||
Write-Host "For higher-fidelity testing (isolated lab VM only):" -ForegroundColor DarkGray
|
||||
Write-Host " 1. rundll32.exe comsvcs.dll MiniDump <lsass_pid> C:\Temp\test.dmp full"
|
||||
Write-Host " 2. procdump.exe -accepteula -ma lsass.exe C:\Temp\lsass.dmp"
|
||||
Write-Host " 3. These generate authentic EID 10 with dbgcore.dll in CallTrace"
|
||||
Write-Host ""
|
||||
@@ -0,0 +1,82 @@
|
||||
title: 'LSASS Credential Dump: Non-Standard Process with Dump Mechanism and Suspicious Access Rights'
|
||||
id: 2abc46f9-9c70-47cf-932e-fe803e06f5c7
|
||||
status: experimental
|
||||
description: >
|
||||
High-fidelity detection for LSASS credential dumping. Detects a non-standard process
|
||||
(outside System32 and Program Files) opening a handle to lsass.exe with credential-dump
|
||||
access rights where the CallTrace reveals MiniDumpWriteDump usage (dbgcore.dll,
|
||||
dbghelp.dll) or direct syscall evasion (UNKNOWN). This triple-AND (suspicious access
|
||||
mask, dump mechanism fingerprint, and non-standard source path) eliminates virtually
|
||||
all legitimate LSASS access. AV/EDR products run from Program Files with clean
|
||||
CallTraces; attack tools run from temp paths with dbgcore.dll or UNKNOWN stacks.
|
||||
A secondary selection covers handle duplication (GrantedAccess 0x0040) from non-standard
|
||||
paths, the HandleKatz and nanodump evasion technique that uses NtDuplicateObject to
|
||||
clone an existing LSASS handle instead of requesting a direct read handle. This
|
||||
GrantedAccess value targeting lsass.exe from outside System32/Program Files has no
|
||||
legitimate use case. Supplementary detections for comsvcs.dll MiniDump LOLBin
|
||||
(process_creation), SSP injection (image_load), and dump file artifacts (file_event)
|
||||
should be implemented as companion rules at the SIEM level for coverage across event
|
||||
types. If this rule fires, assume credential compromise and begin host isolation.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1003/001/
|
||||
- https://github.com/fortra/nanodump
|
||||
- https://github.com/codewhitesec/HandleKatz
|
||||
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
|
||||
- https://www.microsoft.com/en-us/security/blog/2022/10/05/detecting-and-preventing-lsass-credential-dumping-attacks/
|
||||
- https://unit42.paloaltonetworks.com/mimikatz-overview/
|
||||
author: "@NovaSky0x1"
|
||||
date: 2026/03/30
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003.001
|
||||
- attack.t1003
|
||||
- detection.maturity.analyst
|
||||
logsource:
|
||||
category: process_access
|
||||
product: windows
|
||||
detection:
|
||||
selection_lsass_target:
|
||||
TargetImage|endswith: '\lsass.exe'
|
||||
GrantedAccess|contains:
|
||||
- '0x1FFFFF'
|
||||
- '0x1010'
|
||||
- '0x1410'
|
||||
- '0x0810'
|
||||
- '0x1038'
|
||||
- '0x1438'
|
||||
selection_dump_mechanism:
|
||||
CallTrace|contains:
|
||||
- 'dbgcore.dll'
|
||||
- 'dbghelp.dll'
|
||||
- 'UNKNOWN'
|
||||
selection_nonstandard_source:
|
||||
SourceImage|not|startswith:
|
||||
- 'C:\Windows\System32\'
|
||||
- 'C:\Windows\SysWOW64\'
|
||||
- 'C:\Program Files\'
|
||||
- 'C:\Program Files (x86)\'
|
||||
selection_handle_duplication:
|
||||
TargetImage|endswith: '\lsass.exe'
|
||||
GrantedAccess: '0x0040'
|
||||
SourceImage|not|startswith:
|
||||
- 'C:\Windows\System32\'
|
||||
- 'C:\Windows\SysWOW64\'
|
||||
- 'C:\Program Files\'
|
||||
- 'C:\Program Files (x86)\'
|
||||
filter_os_core:
|
||||
SourceImage|startswith:
|
||||
- 'C:\Windows\System32\csrss.exe'
|
||||
- 'C:\Windows\System32\lsass.exe'
|
||||
- 'C:\Windows\System32\services.exe'
|
||||
- 'C:\Windows\System32\svchost.exe'
|
||||
- 'C:\Windows\System32\wininit.exe'
|
||||
- 'C:\Windows\System32\lsaiso.exe'
|
||||
- 'C:\Windows\System32\smss.exe'
|
||||
- 'C:\Windows\System32\winlogon.exe'
|
||||
condition: >
|
||||
(selection_lsass_target and selection_dump_mechanism and selection_nonstandard_source and not filter_os_core)
|
||||
or selection_handle_duplication
|
||||
falsepositives:
|
||||
- Portable diagnostic tools run by administrators from non-standard paths that access LSASS (should be blocked by policy in hardened environments)
|
||||
- Authorized red team or penetration testing tools during sanctioned engagements
|
||||
level: high
|
||||
@@ -0,0 +1,94 @@
|
||||
title: LSASS Access with Suspicious CallTrace or Non-Standard Source Path
|
||||
id: 3d932b09-9d74-428d-bb0f-9368b28c6bb9
|
||||
status: experimental
|
||||
description: >
|
||||
Hunt-level detection for LSASS credential dumping. Adds behavioral context to the
|
||||
research baseline to separate attack tooling from legitimate security products.
|
||||
CallTrace analysis reveals the mechanism used to read LSASS memory: dbgcore.dll
|
||||
and dbghelp.dll indicate MiniDumpWriteDump (ProcDump, comsvcs.dll, custom dump
|
||||
tools), while UNKNOWN indicates direct syscalls or ntdll unhooking. Legitimate
|
||||
AV/EDR products produce clean API call stacks without these indicators. Source
|
||||
path filtering captures tools staged in user-writable directories; attack tools
|
||||
land in Temp, Downloads, AppData while legitimate security products run from
|
||||
Program Files. This rule excludes known AV/EDR paths and WerFault to reduce the
|
||||
research baseline to actionable hunt leads.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1003/001/
|
||||
- https://github.com/fortra/nanodump
|
||||
- https://github.com/codewhitesec/HandleKatz
|
||||
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
|
||||
- https://www.microsoft.com/en-us/security/blog/2022/10/05/detecting-and-preventing-lsass-credential-dumping-attacks/
|
||||
author: "@NovaSky0x1"
|
||||
date: 2026/03/30
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003.001
|
||||
- attack.t1003
|
||||
- detection.maturity.hunt
|
||||
logsource:
|
||||
category: process_access
|
||||
product: windows
|
||||
detection:
|
||||
selection_lsass_access:
|
||||
TargetImage|endswith: '\lsass.exe'
|
||||
GrantedAccess|contains:
|
||||
- '0x1FFFFF'
|
||||
- '0x1010'
|
||||
- '0x1410'
|
||||
- '0x0810'
|
||||
- '0x1038'
|
||||
- '0x1438'
|
||||
- '0x0040'
|
||||
selection_suspicious_calltrace:
|
||||
CallTrace|contains:
|
||||
- 'dbgcore.dll'
|
||||
- 'dbghelp.dll'
|
||||
- 'UNKNOWN'
|
||||
selection_suspicious_source_path:
|
||||
SourceImage|contains:
|
||||
- '\Temp\'
|
||||
- '\tmp\'
|
||||
- '\Downloads\'
|
||||
- '\AppData\'
|
||||
- '\Users\Public\'
|
||||
- '\ProgramData\'
|
||||
- '\Desktop\'
|
||||
- '\Recycle'
|
||||
filter_os_core:
|
||||
SourceImage|startswith:
|
||||
- 'C:\Windows\System32\csrss.exe'
|
||||
- 'C:\Windows\System32\lsass.exe'
|
||||
- 'C:\Windows\System32\services.exe'
|
||||
- 'C:\Windows\System32\svchost.exe'
|
||||
- 'C:\Windows\System32\wininit.exe'
|
||||
- 'C:\Windows\System32\lsaiso.exe'
|
||||
- 'C:\Windows\System32\smss.exe'
|
||||
- 'C:\Windows\System32\winlogon.exe'
|
||||
filter_security_products:
|
||||
SourceImage|contains:
|
||||
- '\Program Files\Windows Defender\'
|
||||
- '\Program Files\Microsoft Security Client\'
|
||||
- '\Program Files\CrowdStrike\'
|
||||
- '\Program Files\SentinelOne\'
|
||||
- '\Program Files\Cylance\'
|
||||
- '\Program Files\Carbon Black\'
|
||||
- '\Program Files\Sophos\'
|
||||
- '\Program Files\ESET\'
|
||||
- '\Program Files\Kaspersky\'
|
||||
- '\Program Files\Trend Micro\'
|
||||
- '\Program Files (x86)\Trend Micro\'
|
||||
- '\Program Files\Bitdefender\'
|
||||
- '\Program Files\Malwarebytes\'
|
||||
- '\Program Files\Palo Alto Networks\'
|
||||
filter_werfault:
|
||||
SourceImage|endswith: '\WerFault.exe'
|
||||
condition: >
|
||||
selection_lsass_access
|
||||
and (selection_suspicious_calltrace or selection_suspicious_source_path)
|
||||
and not (filter_os_core or filter_security_products or filter_werfault)
|
||||
falsepositives:
|
||||
- IT administrators running portable diagnostic tools from non-standard paths that inspect LSASS
|
||||
- Custom monitoring agents installed outside Program Files that query process information
|
||||
- Authorized penetration testing tools during sanctioned engagements
|
||||
- Third-party security products not in the exclusion list (requires environment-specific tuning)
|
||||
level: medium
|
||||
@@ -0,0 +1,58 @@
|
||||
title: LSASS Memory Access by Non-System Process (Research Baseline)
|
||||
id: c08fffe8-ab3c-4e16-abd8-61e648faf95b
|
||||
status: experimental
|
||||
description: >
|
||||
Detects any non-core-OS process opening a handle to lsass.exe with memory-read
|
||||
access rights. This research-level rule establishes a baseline of all LSASS
|
||||
access in the environment (AV/EDR products, WerFault, Task Manager, monitoring
|
||||
tools, and actual attacks) all appear. Run this for one week to build an
|
||||
environment-specific allowlist of legitimate LSASS accessors before tuning to
|
||||
Hunt level. The chokepoint is invariant: every credential dumping tool (Mimikatz,
|
||||
nanodump, comsvcs.dll, ProcDump, HandleKatz, direct syscall loaders) must obtain
|
||||
a kernel handle to lsass.exe. Sysmon Event ID 10 captures this regardless of the
|
||||
API path used.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1003/001/
|
||||
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
|
||||
- https://github.com/fortra/nanodump
|
||||
author: "@NovaSky0x1"
|
||||
date: 2026/03/30
|
||||
tags:
|
||||
- attack.credential_access
|
||||
- attack.t1003.001
|
||||
- attack.t1003
|
||||
- detection.maturity.research
|
||||
logsource:
|
||||
category: process_access
|
||||
product: windows
|
||||
detection:
|
||||
selection:
|
||||
TargetImage|endswith: '\lsass.exe'
|
||||
GrantedAccess|contains:
|
||||
- '0x1FFFFF' # PROCESS_ALL_ACCESS
|
||||
- '0x1010' # PROCESS_VM_READ | PROCESS_QUERY_LIMITED_INFORMATION (Mimikatz classic)
|
||||
- '0x1410' # PROCESS_VM_READ | PROCESS_QUERY_INFORMATION | PROCESS_QUERY_LIMITED_INFORMATION
|
||||
- '0x0810' # PROCESS_VM_READ | PROCESS_QUERY_INFORMATION (nanodump)
|
||||
- '0x1038' # PROCESS_VM_READ | PROCESS_VM_WRITE | PROCESS_VM_OPERATION
|
||||
- '0x1438' # PROCESS_VM_READ | PROCESS_VM_WRITE | PROCESS_VM_OPERATION | PROCESS_QUERY_INFORMATION
|
||||
- '0x0040' # PROCESS_DUP_HANDLE (handle duplication, HandleKatz, nanodump duphandle mode)
|
||||
- '0x0010' # PROCESS_VM_READ alone
|
||||
filter_os_core:
|
||||
SourceImage|startswith:
|
||||
- 'C:\Windows\System32\csrss.exe'
|
||||
- 'C:\Windows\System32\lsass.exe'
|
||||
- 'C:\Windows\System32\services.exe'
|
||||
- 'C:\Windows\System32\svchost.exe'
|
||||
- 'C:\Windows\System32\wininit.exe'
|
||||
- 'C:\Windows\System32\lsaiso.exe'
|
||||
- 'C:\Windows\System32\smss.exe'
|
||||
- 'C:\Windows\System32\winlogon.exe'
|
||||
condition: selection and not filter_os_core
|
||||
falsepositives:
|
||||
- Antivirus and EDR agents performing routine LSASS inspection (MsMpEng.exe, SentinelAgent.exe, CSFalconService.exe, CylanceSvc.exe)
|
||||
- WerFault.exe collecting crash diagnostics for lsass.exe
|
||||
- Task Manager (taskmgr.exe) when an administrator manually creates a process dump
|
||||
- Performance and diagnostic tools (procexp64.exe, procmon64.exe, perfmon.exe)
|
||||
- WMI provider host (wmiprvse.exe) during certain management queries
|
||||
- Windows Defender Advanced Threat Protection sensor (MsSense.exe)
|
||||
level: informational
|
||||
Reference in New Issue
Block a user