Name: LSASS Credential Dumping Id: c7df4fc6-05da-4a67-8dfa-efcd8e2420e2 MitreIds: - T1003.001 - T1003 - T1547.005 Tactics: - Credential Access Techniques: - 'OS Credential Dumping: LSASS Memory' - OS Credential Dumping - 'Boot or Logon Autostart Execution: Security Support Provider' DetectionPriority: CRITICAL ThreatPrevalence: VERY HIGH DetectionDifficulty: MEDIUM Description: > To extract plaintext credentials, NTLM hashes, or Kerberos tickets from a live Windows system, an attacker must read the memory of the Local Security Authority Subsystem Service (lsass.exe). Windows enforces process isolation at the kernel level: any tool that reads another process's memory must first obtain a handle via NtOpenProcess with appropriate access rights. This kernel-mediated handle request is the chokepoint; it fires regardless of whether the attacker uses Mimikatz, nanodump, comsvcs.dll, ProcDump, direct syscalls, or any future tool. Even techniques that bypass userland API hooks (ntdll unhooking, direct syscalls) still traverse the kernel's ObRegisterCallbacks path, which Sysmon Event ID 10 (ProcessAccess) and ETW Threat Intelligence consume. The attacker cannot read lsass memory without the kernel granting the handle. LastUpdated: '2026-03-30' Author: '@NovaSky0x1' Chokepoints: - Stage: Handle Acquisition Input: Attacker has local admin / SYSTEM privileges on the target Invariant: Any process must request a handle to lsass.exe with memory-read access rights from the Windows kernel. Observable: 'Sysmon EID 10 with TargetImage=lsass.exe showing GrantedAccess and CallTrace fields' WhyCantBypass: > Windows enforces process isolation at the kernel level: NtOpenProcess must be called to obtain a handle, and the kernel's ObRegisterCallbacks fires for every handle request regardless of whether the caller used standard APIs or direct syscalls. LogSources: - Sysmon Event ID 10 (ProcessAccess) - Windows Security Event ID 4656 (Handle Requested) - ETW Microsoft-Windows-Threat-Intelligence (kernel-level telemetry) DetectionTier: Research SigmaRef: sigma-rules/lsass-credential-dumping/research.yml - Stage: Memory Read Input: Attacker holds a valid handle to lsass.exe with memory-read rights Invariant: The process must read lsass.exe virtual memory to extract credential material using NtReadVirtualMemory or MiniDumpWriteDump. Observable: 'Sysmon EID 10 CallTrace showing read mechanism (dbgcore.dll, dbghelp.dll, ntdll.dll, or UNKNOWN for direct syscalls); Sysmon EID 11 if dump written to disk' WhyCantBypass: > Credential material (NTLM hashes, Kerberos tickets, plaintext passwords cached by WDigest/SSP) resides in lsass.exe process memory. There is no file or registry location that contains the same live credential state. LogSources: - 'Sysmon Event ID 10 (ProcessAccess: CallTrace field reveals read mechanism)' - 'Sysmon Event ID 11 (File Create: dump file written to disk)' DetectionTier: Hunt SigmaRef: sigma-rules/lsass-credential-dumping/hunt.yml BypassNote: > Handle duplication (NtDuplicateObject) allows an attacker to clone an existing handle to lsass from another process, producing GrantedAccess 0x0040 instead of the standard read masks. The hunt rule includes this pattern. - Stage: Credential Extraction Input: Attacker has raw LSASS memory contents (live read or dump file on disk) Invariant: The attacker must parse LSASS memory structures or dump file contents to extract usable credentials, producing observable artifacts (either an in-memory read with a suspicious CallTrace, a dump file on disk, or a DLL injected into lsass via SSP). Observable: 'Sysmon EID 10 GrantedAccess + CallTrace correlation for live parse; Sysmon EID 7 for SSP DLL injection (ImageLoaded from non-System32 path); Sysmon EID 11 for dump file written to disk' WhyCantBypass: > Credential structures in lsass memory use Microsoft's internal SSP format. The attacker must either parse them in-process (generating the ProcessAccess event) or write a dump file for offline parsing (generating a FileCreate event). SSP injection (loading a malicious DLL into lsass) generates an ImageLoaded event for a DLL outside System32. LogSources: - 'Sysmon Event ID 10 (ProcessAccess: GrantedAccess + CallTrace correlation)' - 'Sysmon Event ID 7 (Image Loaded: SSP DLL injection into lsass)' - 'Sysmon Event ID 11 (File Create: dump file artifact)' - 'Sysmon Event ID 1 (Process Creation: LOLBin execution)' DetectionTier: Analyst SigmaRef: sigma-rules/lsass-credential-dumping/analyst.yml Variations: - Name: Mimikatz (sekurlsa::logonpasswords) FirstSeen: 2011-Q2 Status: Active SourceURL: https://github.com/gentilkiwi/mimikatz Notes: > The original and most widely documented LSASS credential dumping tool. Opens lsass.exe with PROCESS_ALL_ACCESS (0x1FFFFF) or PROCESS_VM_READ (0x1010). Used by virtually every ransomware group and APT. GrantedAccess 0x1010 is the classic Mimikatz fingerprint. VariantId: mimikatz-sekurlsa Command: Invocation: "privilege::debug\nsekurlsa::logonpasswords\n# Or one-liner:\nmimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit" Context: 'Classic LSASS dumper. Opens handle with 0x1010. Used by virtually every ransomware group and APT.' Artifacts: - 'Sysmon EID 10: GrantedAccess 0x1010, CallTrace contains ntdll.dll' - 'Sysmon EID 1: mimikatz.exe from non-standard path' ChokepointMapping: 'mimikatz.exe launched → handle to lsass.exe (0x1010) → memory read → credentials extracted' - Name: comsvcs.dll MiniDump (LOLBin) FirstSeen: 2019-Q1 Status: Active SourceURL: https://lolbas-project.github.io/#/OtherMSBinaries/Comsvcs Notes: > Living-off-the-land technique using rundll32.exe to call the MiniDump export from comsvcs.dll (a legitimate Windows DLL). Writes a full process dump of lsass.exe to disk. Command pattern: rundll32.exe comsvcs.dll MiniDump full. The MiniDump export name is a fixed Windows API; it cannot be renamed without recompiling the DLL. VariantId: comsvcs-minidump-lolbin Command: Invocation: 'rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump C:\Windows\Temp\dump.dmp full' Context: 'LOLBin technique using a legitimate Windows DLL. Microsoft-signed rundll32.exe calls the MiniDump export. Writes full LSASS dump to disk.' Artifacts: - 'Sysmon EID 1: rundll32.exe with comsvcs.dll and MiniDump in CommandLine' - 'Sysmon EID 10: rundll32.exe accessing lsass.exe, CallTrace contains dbgcore.dll' - 'Sysmon EID 11: .dmp file created in temp directory' ChokepointMapping: 'rundll32.exe invoked → comsvcs.dll MiniDump export called → handle to lsass.exe → dump written to disk' - Name: ProcDump (Sysinternals) FirstSeen: 2016-Q1 Status: Active SourceURL: https://learn.microsoft.com/en-us/sysinternals/downloads/procdump Notes: > Microsoft Sysinternals tool used legitimately for debugging, repurposed for LSASS dumping. Uses MiniDumpWriteDump API (dbgcore.dll/dbghelp.dll in CallTrace). Signed by Microsoft, so it bypasses many application whitelisting policies. VariantId: procdump-sysinternals Command: Invocation: 'procdump.exe -ma lsass.exe C:\Windows\Temp\lsass.dmp' Context: 'Microsoft Sysinternals tool. Signed by Microsoft, bypasses application whitelisting. Uses MiniDumpWriteDump API.' Artifacts: - 'Sysmon EID 1: procdump.exe or procdump64.exe with lsass in CommandLine' - 'Sysmon EID 10: procdump accessing lsass.exe, CallTrace contains dbgcore.dll or dbghelp.dll' - 'Sysmon EID 11: .dmp file created' ChokepointMapping: 'procdump.exe launched → handle to lsass.exe → MiniDumpWriteDump called → dump file written to disk' - Name: Nanodump FirstSeen: 2022-Q1 Status: Active SourceURL: https://github.com/fortra/nanodump Notes: > Minimal LSASS dumper designed to evade detection. Uses direct syscalls, handle duplication, and process forking techniques. GrantedAccess patterns vary: 0x0810 for direct read, 0x0040 for handle duplication mode. Produces UNKNOWN in Sysmon CallTrace when using direct syscalls. VariantId: nanodump Command: Invocation: "nanodump.exe --write C:\\Windows\\Temp\\nano.dmp\n# Or handle duplication mode:\nnanodump.exe --dup --write C:\\Windows\\Temp\\nano.dmp\n# Or direct syscall mode:\nnanodump.exe --syscall --write C:\\Windows\\Temp\\nano.dmp" Context: 'Minimal LSASS dumper with multiple evasion modes. Direct syscalls produce UNKNOWN in CallTrace. Handle duplication produces GrantedAccess 0x0040.' Artifacts: - 'Sysmon EID 10: GrantedAccess 0x0810 (direct) or 0x0040 (dup mode), CallTrace UNKNOWN for syscall mode' - 'Sysmon EID 11: dump file (may use custom format, not standard .dmp)' ChokepointMapping: 'nanodump launched → handle to lsass.exe (direct or duplicated) → memory read via syscall → dump written' - Name: HandleKatz FirstSeen: 2021-Q3 Status: Active SourceURL: https://github.com/codewhitesec/HandleKatz Notes: > Abuses handle duplication to obtain a cloned handle to lsass.exe from another process that already holds one. GrantedAccess 0x0040 (PROCESS_DUP_HANDLE). Designed to evade detections that only look for direct PROCESS_VM_READ handles. VariantId: handlekatz-dup Command: Invocation: 'handlekatz.exe --pid --outfile C:\Windows\Temp\hk.dmp' Context: 'Clones an existing handle to lsass.exe from another process via NtDuplicateObject. Produces GrantedAccess 0x0040 instead of standard read masks.' Artifacts: - 'Sysmon EID 10: GrantedAccess 0x0040 (PROCESS_DUP_HANDLE) targeting lsass.exe' - 'Sysmon EID 10: secondary handle request to the process holding the original lsass handle' ChokepointMapping: 'handlekatz launched → finds process with existing lsass handle → NtDuplicateObject (0x0040) → memory read → credentials extracted' - Name: PPLBlade / PPLdump FirstSeen: 2022-Q3 Status: Active SourceURL: https://github.com/tastypepperoni/PPLBlade Notes: > Bypasses Protected Process Light (PPL) protection on lsass.exe by exploiting vulnerable signed drivers or ELAM driver abuse. Once PPL is defeated, standard dump tools work. Detection shifts to the BYOVD/driver load stage (covered by edr-bypass-techniques) plus the subsequent LSASS access event. VariantId: pplblade-ppldump Command: Invocation: "PPLBlade.exe --mode dump --driver RTCore64.sys --output C:\\Windows\\Temp\\ppl.dmp\n# Or PPLdump:\nPPLdump.exe C:\\Windows\\Temp\\ppl.dmp" Context: 'Two-stage attack: loads a vulnerable signed driver to disable PPL on lsass.exe, then performs standard dump. Detection shifts to the BYOVD driver load stage plus subsequent LSASS access.' Artifacts: - 'Sysmon EID 6: vulnerable driver loaded (RTCore64.sys, DBUtil_2_3.sys, etc.)' - 'Sysmon EID 10: LSASS access after PPL disabled, standard access mask' - 'Sysmon EID 11: dump file written to disk' ChokepointMapping: 'vulnerable driver loaded (EID 6) → PPL disabled on lsass.exe → handle to lsass.exe → dump written to disk' - Name: Task Manager Manual Dump FirstSeen: 2014-Q1 Status: Active Notes: > Built-in Windows capability: right-click lsass.exe in Task Manager and select "Create dump file." Writes a full memory dump to %TEMP%. Uses 0x1FFFFF GrantedAccess from taskmgr.exe. Often used by less sophisticated attackers or during hands-on-keyboard intrusions. VariantId: task-manager-manual-dump Command: Invocation: 'Right-click lsass.exe in Task Manager > Create dump file' Context: 'Built-in Windows capability. No tools required. Writes full memory dump to %TEMP%\lsass.DMP. Common in hands-on-keyboard intrusions by less sophisticated attackers.' Artifacts: - 'Sysmon EID 10: taskmgr.exe accessing lsass.exe with GrantedAccess 0x1FFFFF' - 'Sysmon EID 11: lsass.DMP written to %TEMP%' ChokepointMapping: 'taskmgr.exe opened → handle to lsass.exe (0x1FFFFF) → MiniDumpWriteDump → lsass.DMP written to %TEMP%' - Name: SSP Injection (mimilib / memssp) FirstSeen: 2015-Q1 Status: Active SourceURL: https://attack.mitre.org/techniques/T1547/005/ Notes: > Injects a malicious Security Support Provider DLL into lsass.exe via AddSecurityPackage API or direct registry manipulation (HKLM\SYSTEM\CCS\Control\Lsa\Security Packages). The DLL logs all future authentication events to a file. Sysmon EID 7 detects the DLL load from a non-System32 path. VariantId: ssp-injection-mimilib Command: Invocation: "# Mimikatz SSP injection:\nmisc::memssp\n# Or registry-based persistence:\nreg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa /v \"Security Packages\" /t REG_MULTI_SZ /d \"mimilib\" /f" Context: 'Injects a malicious SSP DLL into lsass.exe. Logs all future authentication events to a plaintext file. Persists across reboots via registry. Unlike other variants, this is a persistence mechanism, not a one-time dump.' Artifacts: - 'Sysmon EID 7: DLL loaded into lsass.exe from non-System32 path' - 'Sysmon EID 13: registry modification to HKLM\SYSTEM\CCS\Control\Lsa\Security Packages' - 'Sysmon EID 11: kiwissp.log or similar credential log file created' ChokepointMapping: 'AddSecurityPackage API or registry write → malicious DLL loaded into lsass.exe (EID 7) → credentials logged to file on future authentications' - Name: Direct Syscall Dumpers (SilentProcessExit, MirrorDump, SafetyKatz) FirstSeen: 2020-Q2 Status: Active SourceURL: https://github.com/GhostPack/SafetyKatz Notes: > Family of tools that use direct system calls (syscall stubs) to bypass ntdll.dll userland hooks placed by EDR products. The kernel callback (ObRegisterCallbacks) still fires, so Sysmon EID 10 still generates, but the CallTrace shows UNKNOWN instead of ntdll.dll. MirrorDump uses DLL injection into a process with an existing LSASS handle. VariantId: direct-syscall-dumpers Command: Invocation: "# SafetyKatz (execute-assembly in C2):\nexecute-assembly SafetyKatz.exe\n# MirrorDump:\nMirrorDump.exe --output C:\\Windows\\Temp\\mirror.dmp\n# SilentProcessExit (abuse WER):\nreg add \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\lsass.exe\" /v ReportingMode /t REG_DWORD /d 1 /f" Context: 'Family of tools using direct system call stubs to bypass ntdll.dll userland hooks. Kernel ObRegisterCallbacks still fires. CallTrace shows UNKNOWN instead of ntdll.dll.' Artifacts: - 'Sysmon EID 10: LSASS access with CallTrace containing UNKNOWN' - 'Sysmon EID 1: suspicious process from user-writable path' - 'Sysmon EID 11: dump file (may use non-standard format)' ChokepointMapping: 'tool launched → direct syscall to NtOpenProcess → handle to lsass.exe (UNKNOWN CallTrace) → memory read → dump or live parse' - Name: Pypykatz (Python) FirstSeen: 2019-Q3 Status: Active SourceURL: https://github.com/skelsec/pypykatz Notes: > Pure Python implementation of Mimikatz credential extraction. Can parse LSASS memory dumps offline or access live LSASS via ctypes. Cross-platform, works on Linux for parsing dump files obtained from Windows. Overlaps with BYOSI chokepoint when Python interpreter is brought onto the target. VariantId: pypykatz-python Command: Invocation: "# Live LSASS access via ctypes:\npypykatz live lsa\n# Offline dump parsing:\npypykatz lsa minidump lsass.dmp" Context: 'Pure Python Mimikatz implementation. Can access live LSASS via ctypes or parse dump files offline. Cross-platform for offline parsing. Overlaps with BYOSI chokepoint when Python is brought onto target.' Artifacts: - 'Sysmon EID 10: python.exe or python3.exe accessing lsass.exe' - 'Sysmon EID 1: python.exe running from non-standard path' - 'Sysmon EID 3: python.exe making outbound connection (if exfiltrating)' ChokepointMapping: 'python.exe launched → ctypes call to OpenProcess → handle to lsass.exe → memory read via ctypes → credentials parsed in-process' - Name: Impacket secretsdump.py (Remote) FirstSeen: 2016-Q1 Status: Active SourceURL: https://github.com/fortra/impacket Notes: > Remote credential extraction over SMB. Supports multiple modes: DCSync (replicating credentials via DRSUAPI), remote registry SAM/LSA dump, and remote LSASS memory read via svcctl service creation. When using the LSASS read mode, the service runs on the target and dumps locally. Overlaps with the remote-execution-tools chokepoint for the SMB lateral movement stage. VariantId: impacket-secretsdump Command: Invocation: "# Remote LSASS dump via svcctl:\nsecretsdump.py domain/user:password@target -just-dc-ntlm\n# Or with pass-the-hash:\nsecretsdump.py -hashes :NTLM_HASH domain/user@target" Context: 'Remote credential extraction over SMB. The LSASS access event occurs on the target host via a remotely created service. Supports DCSync (DRSUAPI), remote registry SAM/LSA dump, and remote LSASS read.' Artifacts: - 'Sysmon EID 10: service process accessing lsass.exe on target host' - 'Security EID 4624: network logon (Type 3) from attacker IP' - 'Security EID 7045: new service created via svcctl' ChokepointMapping: 'SMB authentication → svcctl service creation on target → service process handles lsass.exe → credentials extracted remotely' - Name: CrackMapExec / NetExec (--lsa, --sam) FirstSeen: 2019-Q2 Status: Active SourceURL: https://github.com/Pennyw0rth/NetExec Notes: > Network-based credential harvesting across multiple hosts. The --lsa and --sam flags dump credentials remotely via SMB service creation. The LSASS access event occurs on the target host, not the attacker's machine. Used heavily in ransomware operations for credential spraying across domains. VariantId: crackmapexec-netexec Command: Invocation: "# Dump LSA secrets across multiple hosts:\nnxc smb 10.0.0.0/24 -u admin -p password --lsa\n# Dump SAM hive:\nnxc smb target -u admin -p password --sam" Context: 'Network-based credential harvesting across multiple hosts via SMB service creation. LSASS access occurs on each target host, not the attacker machine. Used heavily in ransomware operations for domain-wide credential spraying.' Artifacts: - 'Sysmon EID 10: remotely created service process accessing lsass.exe on each target' - 'Security EID 7045: new service created on each target host' - 'Security EID 4624: network logon (Type 3) from attacker IP across multiple hosts' ChokepointMapping: 'SMB spray across subnet → service created per host → each service handles lsass.exe → credentials collected centrally' - Name: Cobalt Strike (logonpasswords, hashdump) FirstSeen: 2014-Q1 Status: Active Notes: > Built-in beacon commands for credential theft. logonpasswords injects Mimikatz reflectively into memory; hashdump reads the SAM hive. Both generate Sysmon EID 10 for the LSASS access. The source process is the beacon's host process (often rundll32.exe or a sacrificial process), producing a non-standard source path in most deployments. VariantId: cobalt-strike-logonpasswords Command: Invocation: "# Beacon commands:\nlogonpasswords\nhashdump\n# Or via execute-assembly:\nexecute-assembly /path/to/SharpKatz.exe" Context: 'Built-in beacon commands. logonpasswords reflectively injects Mimikatz into memory. Source process is the beacon host process (often rundll32.exe or sacrificial process), producing a non-standard SourceImage in EID 10.' Artifacts: - 'Sysmon EID 10: beacon host process (e.g., rundll32.exe) accessing lsass.exe' - 'Sysmon EID 1: sacrificial process spawned by beacon' - 'Sysmon EID 8: CreateRemoteThread into lsass.exe (reflective injection)' ChokepointMapping: 'beacon receives task → reflective Mimikatz injection or execute-assembly → handle to lsass.exe from beacon host process → credentials returned to C2' - Name: Sliver (creds, sharp-dump) FirstSeen: 2020-Q1 Status: Active SourceURL: https://github.com/BishopFox/sliver Notes: > Open-source C2 framework from BishopFox. Supports credential dumping via execute-assembly (loading SharpDump or SharpKatz in-process) and through built-in BOF (Beacon Object File) execution. The LSASS access originates from the Sliver implant process, which typically runs from a user-writable path or injected into a legitimate process. VariantId: sliver-creds Command: Invocation: "# Built-in credential dump:\ncreds\n# Or execute-assembly with SharpDump:\nexecute-assembly -t 60 SharpDump.exe\n# Or BOF execution:\nbof /path/to/nanodump.o" Context: 'Open-source C2 from BishopFox. Credential dumping via execute-assembly (SharpDump/SharpKatz) or BOF execution. LSASS access originates from the Sliver implant process, typically running from a user-writable path or injected into a legitimate process.' Artifacts: - 'Sysmon EID 10: Sliver implant process accessing lsass.exe' - 'Sysmon EID 1: implant process running from user-writable path' - 'Sysmon EID 11: dump file if using SharpDump' ChokepointMapping: 'Sliver implant receives task → execute-assembly or BOF loads dump tool in-process → handle to lsass.exe → credentials returned to C2' - Name: Havoc (mimikatz, coffloader) FirstSeen: 2022-Q3 Status: Active SourceURL: https://github.com/HavocFramework/Havoc Notes: > Open-source C2 framework with built-in Mimikatz integration and COFFLoader for executing credential dumping BOFs. The LSASS access event comes from the Havoc demon process. Gaining popularity as a Cobalt Strike alternative in both red team and threat actor operations. VariantId: havoc-mimikatz Command: Invocation: "# Havoc demon commands:\nmimikatz\n# Or COFFLoader for BOF-based dump:\ncoffloader /path/to/nanodump.o" Context: 'Open-source C2 with built-in Mimikatz and COFFLoader for BOFs. Gaining popularity as a Cobalt Strike alternative in both red team and threat actor operations. LSASS access comes from the Havoc demon process.' Artifacts: - 'Sysmon EID 10: Havoc demon process accessing lsass.exe' - 'Sysmon EID 1: demon process, often masquerading as legitimate binary' - 'Sysmon EID 3: demon outbound C2 connection' ChokepointMapping: 'Havoc demon receives task → Mimikatz or BOF loaded in-process → handle to lsass.exe → credentials returned to teamserver' - Name: Brute Ratel C4 (brc4, credstore) FirstSeen: 2022-Q1 Status: Active Notes: > Commercial adversary simulation tool that has been adopted by ransomware operators (notably BlackCat/ALPHV). Includes built-in credential harvesting capabilities. Uses syscall-level evasion techniques similar to nanodump, producing UNKNOWN in Sysmon CallTrace. Leaked versions circulate in criminal forums. VariantId: brute-ratel-credstore Command: Invocation: "# BRC4 badger commands:\ncredstore collect\n# Or integrated Mimikatz:\nmimikatz sekurlsa::logonpasswords" Context: 'Commercial adversary simulation tool adopted by ransomware operators (BlackCat/ALPHV). Uses syscall-level evasion similar to nanodump, producing UNKNOWN in CallTrace. Leaked versions circulate in criminal forums.' Artifacts: - 'Sysmon EID 10: badger process accessing lsass.exe, CallTrace UNKNOWN' - 'Sysmon EID 1: badger process, often injected into legitimate process' - 'Sysmon EID 3: encrypted C2 channel' ChokepointMapping: 'BRC4 badger receives task → syscall-level LSASS access (UNKNOWN CallTrace) → handle to lsass.exe → credentials returned to C2' - Name: Mythic (Athena, Apollo agents) FirstSeen: 2020-Q2 Status: Active SourceURL: https://github.com/its-a-feature/Mythic Notes: > Open-source C2 platform with modular agent architecture. Credential dumping is implemented through agent-specific modules (Athena, Apollo) that call MiniDumpWriteDump or use direct syscalls. The source process varies by agent configuration and injection method. VariantId: mythic-agents Command: Invocation: "# Apollo agent (C#):\nmimikatz sekurlsa::logonpasswords\n# Athena agent (cross-platform):\nassembly -f SharpKatz.exe\n# Or BOF:\nbof nanodump.o" Context: 'Open-source C2 with modular agent architecture. Credential dumping via agent-specific modules that call MiniDumpWriteDump or use direct syscalls. Source process varies by agent configuration and injection method.' Artifacts: - 'Sysmon EID 10: agent process accessing lsass.exe' - 'Sysmon EID 1: agent process, varies by configuration (may be injected into legitimate process)' - 'Sysmon EID 11: dump file if using MiniDumpWriteDump-based modules' ChokepointMapping: 'Mythic agent receives task → credential module loaded → handle to lsass.exe → credentials returned to Mythic server' - Name: Dumpert FirstSeen: 2019-Q3 Status: Active SourceURL: https://github.com/outflanknl/Dumpert Notes: > One of the first public tools to use direct system calls for LSASS dumping, bypassing ntdll.dll API hooks. Calls NtOpenProcess and NtCreateFile via syscall stubs. Produces UNKNOWN in Sysmon CallTrace. Foundational technique adopted by nanodump and subsequent evasion tools. VariantId: dumpert-direct-syscall Command: Invocation: 'Outflank-Dumpert.exe' Context: 'One of the first public tools to use direct syscall stubs for LSASS dumping. Foundational technique adopted by nanodump and subsequent evasion tools. Calls NtOpenProcess and NtCreateFile via syscall stubs, bypassing ntdll.dll hooks.' Artifacts: - 'Sysmon EID 10: LSASS access with CallTrace UNKNOWN (syscall stubs bypass ntdll.dll)' - 'Sysmon EID 1: Dumpert binary from user-writable path' - 'Sysmon EID 11: dump file written via NtCreateFile syscall' ChokepointMapping: 'Dumpert launched → NtOpenProcess via syscall stub (UNKNOWN CallTrace) → handle to lsass.exe → NtCreateFile writes dump to disk' - Name: SharpKatz / SharpDump (.NET) FirstSeen: 2019-Q1 Status: Active SourceURL: https://github.com/GhostPack/SharpDump Notes: > C# implementations of credential dumping designed for execute-assembly workflows in Cobalt Strike, Sliver, and similar frameworks. SharpKatz reimplements Mimikatz in .NET; SharpDump creates a minidump of LSASS. Both use MiniDumpWriteDump (dbgcore.dll in CallTrace) and run from the beacon's process context. VariantId: sharpkatz-sharpdump-dotnet Command: Invocation: "# SharpDump (minidump):\nSharpDump.exe\n# SharpKatz (in-memory parse):\nSharpKatz.exe --Command logonpasswords\n# Typically via execute-assembly in C2:\nexecute-assembly SharpDump.exe" Context: 'C# implementations designed for execute-assembly workflows in Cobalt Strike, Sliver, and similar frameworks. Both use MiniDumpWriteDump (dbgcore.dll in CallTrace) and run from the beacon process context.' Artifacts: - 'Sysmon EID 10: beacon/host process accessing lsass.exe, CallTrace contains dbgcore.dll' - 'Sysmon EID 11: .dmp file written (SharpDump writes to %TEMP% with .bin extension)' - 'Sysmon EID 1: .NET assembly loaded in-process (no new process for execute-assembly)' ChokepointMapping: 'execute-assembly loads .NET tool in beacon process → MiniDumpWriteDump called (dbgcore.dll in CallTrace) → handle to lsass.exe → dump written or parsed in-memory' - Name: Out-Minidump (PowerShell) FirstSeen: 2016-Q3 Status: Declining SourceURL: https://github.com/PowerShellMafia/PowerSploit Notes: > PowerShell-based LSASS dump using .NET P/Invoke to call MiniDumpWriteDump. Part of the PowerSploit toolkit. Generates both a PowerShell script block log and Sysmon EID 10. Less common now due to AMSI and Script Block Logging making PowerShell-based attacks more visible. VariantId: out-minidump-powershell Command: Invocation: "# PowerSploit:\nImport-Module .\\Out-Minidump.ps1\nGet-Process lsass | Out-Minidump -DumpFilePath C:\\Windows\\Temp\\lsass.dmp" Context: 'PowerShell-based dump using .NET P/Invoke to call MiniDumpWriteDump. Part of PowerSploit toolkit. Declining use due to AMSI and Script Block Logging making PowerShell attacks more visible.' Artifacts: - 'Sysmon EID 10: powershell.exe accessing lsass.exe, CallTrace contains dbgcore.dll' - 'PowerShell Script Block Log (EID 4104): Out-Minidump function and MiniDumpWriteDump P/Invoke' - 'Sysmon EID 11: .dmp file created' ChokepointMapping: 'powershell.exe loads Out-Minidump → P/Invoke calls MiniDumpWriteDump → handle to lsass.exe (dbgcore.dll in CallTrace) → dump written to disk' - Name: LSASS Shtinkering (Process Snapshotting) FirstSeen: 2022-Q1 Status: Emerging SourceURL: https://github.com/deepinstinct/Lsass-Shtinkering Notes: > Uses PssNtCaptureSnapshot to create a snapshot of the LSASS process, then reads credentials from the snapshot instead of live memory. The snapshot API still requires a handle to lsass.exe, so Sysmon EID 10 fires, but the GrantedAccess mask may differ from standard dump patterns. Some EDR products do not monitor snapshot operations. VariantId: lsass-shtinkering-snapshot Command: Invocation: 'LsassShtinkering.exe --output C:\Windows\Temp\snapshot.dmp' Context: 'Uses PssNtCaptureSnapshot to create a snapshot of LSASS, then reads credentials from the snapshot. Snapshot API still requires a handle to lsass.exe (EID 10 fires), but GrantedAccess mask may differ from standard dump patterns. Some EDR products do not monitor snapshot operations.' Artifacts: - 'Sysmon EID 10: process accessing lsass.exe with non-standard GrantedAccess for snapshot' - 'Sysmon EID 1: tool binary from user-writable path' - 'Sysmon EID 11: snapshot dump file written to disk' ChokepointMapping: 'tool launched → PssNtCaptureSnapshot requires handle to lsass.exe (EID 10) → snapshot created → credentials parsed from snapshot' - Name: Skeleton Key (SSP Backdoor) FirstSeen: 2015-Q1 Status: Active SourceURL: https://attack.mitre.org/software/S0007/ Notes: > Variant of SSP injection that patches the LSASS authentication flow to accept a universal "skeleton key" password for any domain account. Unlike mimilib which logs credentials, Skeleton Key modifies authentication in-memory. Detected via Sysmon EID 7 (DLL loaded into lsass from non-System32 path) and anomalous Kerberos authentication patterns. VariantId: skeleton-key-ssp Command: Invocation: "# Mimikatz Skeleton Key:\nmisc::skeleton\n# Patches LSASS in-memory to accept master password for any domain account" Context: 'Patches the LSASS authentication flow to accept a universal skeleton key password. Unlike mimilib which logs credentials, Skeleton Key modifies authentication in-memory. Detected via DLL injection into lsass and anomalous Kerberos patterns.' Artifacts: - 'Sysmon EID 7: DLL loaded into lsass.exe from non-System32 path' - 'Sysmon EID 10: process accessing lsass.exe for in-memory patching' - 'Security EID 4769: anomalous Kerberos TGS requests using skeleton key' ChokepointMapping: 'tool injects into lsass.exe (EID 7) → authentication flow patched in-memory → skeleton key password accepted for any account → detected via anomalous Kerberos patterns' - Name: LaZagne FirstSeen: 2015-Q1 Status: Active SourceURL: https://github.com/AlessandroZ/LaZagne Notes: > Multi-platform credential harvester that extracts passwords from browsers, databases, mail clients, Wi-Fi, and LSASS. Uses ctypes on Windows to call OpenProcess against lsass.exe. Cross-platform (Python), often deployed alongside BYOSI techniques. VariantId: lazagne-multi-platform Command: Invocation: "# All credentials including LSASS:\nlaZagne.exe all\n# LSASS-specific:\nlaZagne.exe windows -m lsa_secrets" Context: 'Multi-platform credential harvester. Uses ctypes on Windows to call OpenProcess against lsass.exe. Cross-platform (Python), often deployed alongside BYOSI techniques. Extracts passwords from browsers, databases, mail clients, Wi-Fi, and LSASS.' Artifacts: - 'Sysmon EID 10: laZagne.exe or python.exe accessing lsass.exe' - 'Sysmon EID 1: laZagne binary or Python interpreter from user-writable path' - 'Sysmon EID 11: credential output file if using -oN or -oJ flags' ChokepointMapping: 'laZagne launched → OpenProcess via ctypes → handle to lsass.exe → credentials parsed from multiple sources including LSASS' - Name: EDRSandBlast (LSASS dump mode) FirstSeen: 2022-Q4 Status: Active SourceURL: https://github.com/wavestone-cdt/EDRSandblast Notes: > Combines BYOVD driver exploitation with LSASS credential dumping in a single tool. Loads a vulnerable driver to blind EDR kernel callbacks, then dumps LSASS. The driver load is detectable via Sysmon EID 6 (see edr-bypass-techniques); the LSASS access still generates EID 10 if Sysmon kernel callbacks survive the patching attempt. VariantId: edrsandblast-lsass Command: Invocation: "EDRSandblast.exe --usermode --kernelmode --dump-lsass\n# Loads vulnerable driver, patches EDR callbacks, then dumps LSASS" Context: 'Combines BYOVD driver exploitation with LSASS dumping in a single tool. Loads a vulnerable driver to blind EDR kernel callbacks, then dumps LSASS. Two-stage detection: driver load (EID 6) then LSASS access (EID 10 if callbacks survive).' Artifacts: - 'Sysmon EID 6: vulnerable driver loaded (e.g., RTCore64.sys, DBUtil_2_3.sys)' - 'Sysmon EID 10: LSASS access (if kernel callbacks survive the patching attempt)' - 'Sysmon EID 11: dump file written to disk' ChokepointMapping: 'vulnerable driver loaded (EID 6) → EDR kernel callbacks patched → handle to lsass.exe (EID 10 if Sysmon survives) → dump written to disk' Prerequisites: - The attacker must have local administrator or SYSTEM privileges on the target host (LSASS access requires SeDebugPrivilege or equivalent) - LSASS must not be running as a Protected Process Light (PPL), or the attacker must first bypass PPL (see edr-bypass-techniques) - Credential Guard (VBS) must not be active, or the attacker must compromise the isolated LSA environment (significantly harder, no known public tools) - Sysmon or equivalent kernel-level telemetry must be deployed for chokepoint visibility (Security EID 4656 provides partial coverage without Sysmon) EvolutionTimeline: - Date: 2011-Q2 Event: Mimikatz released by Benjamin Delpy Change: > First publicly available tool for extracting plaintext credentials from LSASS memory. Used PROCESS_ALL_ACCESS (0x1FFFFF) handle with standard Windows API calls through ntdll.dll. DetectionImpact: > No detection existed. LSASS memory access was not monitored by any standard Windows audit configuration. Security products relied on signature-based detection of the Mimikatz binary itself. TheConstant: A process must open a handle to lsass.exe and read its virtual memory Variants: [] EventType: event - Date: 2016-Q1 Event: 'LOLBin techniques emerge: ProcDump and comsvcs.dll repurposed for LSASS dumping' Change: > Attackers shifted from custom tools to Microsoft-signed binaries (procdump.exe, rundll32.exe + comsvcs.dll) to bypass application whitelisting and signature detection. The dump is written to disk for offline parsing. DetectionImpact: > Binary signature detection bypassed completely. Detection shifted to process creation monitoring for known LOLBin command patterns and file creation events for .dmp files in temp directories. TheConstant: A process must open a handle to lsass.exe and read its virtual memory Variants: [] EventType: event - Date: 2019-Q2 Event: Sysmon EID 10 (ProcessAccess) adopted as primary LSASS monitoring source Change: > Microsoft Sysinternals added ProcessAccess logging to Sysmon, providing kernel-level visibility into handle requests targeting lsass.exe. The GrantedAccess and CallTrace fields became the foundation for behavioral LSASS access detection independent of specific tool signatures. DetectionImpact: > Transformed LSASS monitoring from signature-based to behavior-based. Defenders could now detect any tool accessing LSASS by its access mask and calling mechanism rather than its binary name or hash. TheConstant: A process must open a handle to lsass.exe and read its virtual memory Variants: [] EventType: event - Date: 2020-Q2 Event: Direct syscall and ntdll unhooking techniques proliferate Change: > Tools like SilentProcessExit, MirrorDump, and custom loaders bypass EDR userland hooks by making system calls directly to the kernel, skipping ntdll.dll entirely. This produces UNKNOWN in Sysmon CallTrace instead of the standard ntdll.dll entry. DetectionImpact: > EDR products relying on ntdll.dll API hooks lost visibility. Sysmon EID 10 still fires because the kernel ObRegisterCallbacks mechanism operates below the userland hook layer. UNKNOWN in CallTrace became a detection signal rather than a blind spot. TheConstant: A process must open a handle to lsass.exe and read its virtual memory Variants: [] EventType: event - Date: 2021-Q3 Event: Handle duplication evasion (HandleKatz, nanodump duphandle mode) Change: > Instead of directly opening lsass.exe, these tools open a different process that already holds a handle to lsass, then duplicate that handle via NtDuplicateObject. This produces GrantedAccess 0x0040 (PROCESS_DUP_HANDLE) rather than the expected 0x1010 or 0x1FFFFF. DetectionImpact: > Detection rules looking only for PROCESS_VM_READ or PROCESS_ALL_ACCESS missed the duplication pattern. Rules updated to include 0x0040 as a suspicious GrantedAccess value when targeting lsass.exe from a non-standard source path. TheConstant: A process must open a handle to lsass.exe and read its virtual memory Variants: [] EventType: event - Date: 2022-Q3 Event: PPL bypass tools combine BYOVD with LSASS dumping Change: > PPLBlade, PPLdump, and similar tools load a vulnerable signed kernel driver to disable Protected Process Light on lsass.exe before performing the dump. Two-stage attack: driver load (EID 6) precedes LSASS access (EID 10). DetectionImpact: > PPL protection is defeated before the dump occurs, so the LSASS access event appears normal from an access-rights perspective. Detection requires correlating the vulnerable driver load with subsequent LSASS access. See edr-bypass-techniques for the driver load stage. TheConstant: A process must open a handle to lsass.exe and read its virtual memory Variants: [] EventType: event - Date: 2024-Q3 Event: LSASS credential dumping remains universal across ransomware groups Change: > Kaspersky, Mandiant, and Cisco Talos reports confirm T1003.001 in 5 of 5 major ransomware families (BlackBasta, BlackCat, Akira, Qilin, LockBit). Tool choice varies (Mimikatz, comsvcs.dll, nanodump, custom tools) but the LSASS access event is present in every case. DetectionImpact: > No new evasion of the kernel-level chokepoint. Tool diversity increased but behavioral detection via Sysmon EID 10 remained effective across all variants. TheConstant: A process must open a handle to lsass.exe and read its virtual memory Variants: [] EventType: event EmulationScript: File: emulation/lsass-credential-dumping/emulate.ps1 Language: powershell AtomicRef: T1003.001 Description: Simulates LSASS credential dumping chokepoint stages for detection validation SafetyNotes: > Run in an isolated lab VM with Sysmon deployed. Requires Administrator privileges. Does NOT extract credentials. Opens and immediately closes a handle to lsass.exe to generate EID 10 telemetry, simulates comsvcs.dll command line for EID 1, and creates a marker .dmp file for EID 11. Detections: - Level: Research Description: Baseline all non-system processes accessing lsass.exe with memory-read permissions LogSources: - Sysmon Event ID 10 (ProcessAccess) Logic: 'Any process accessing lsass.exe with credential-dump access masks (0x1010, 0x1FFFFF, 0x1410, 0x0810, 0x0040, 0x1038, 0x1438). Filter core OS processes only (csrss, services, svchost, lsaiso, wininit, smss, winlogon). Everything else, including AV/EDR and WerFault, appears here. Run for a week to build the environment-specific allowlist.' ExpectedFPRate: High UseCase: > Detection engineers baselining LSASS access patterns in a new environment. Identifies which processes normally touch LSASS to build the environment-specific allowlist needed for Hunt and Analyst rules. SigmaRule: sigma-rules/lsass-credential-dumping/research.yml - Level: Hunt Description: LSASS access with suspicious CallTrace, non-standard source path, or LOLBin dump pattern LogSources: - Sysmon Event ID 10 (ProcessAccess) - Sysmon Event ID 1 (Process Creation) Logic: 'LSASS access with credential-dump access masks AND one of: CallTrace through dbgcore/dbghelp (MiniDumpWriteDump signature), UNKNOWN CallTrace (direct syscall), SourceImage in a user-writable path (Temp, Downloads, AppData, ProgramData, Users\Public), or process creation matching the rundll32 comsvcs MiniDump or procdump LOLBin patterns. Exclude core OS and known AV/EDR install paths.' ExpectedFPRate: Medium UseCase: > Active threat hunting for credential dumping. Periodic sweeps during incident response or campaign investigations. CallTrace analysis separates legitimate security product access from dump tooling behavior. SigmaRule: sigma-rules/lsass-credential-dumping/hunt.yml - Level: Analyst Description: Non-standard process accessing LSASS with dump mechanism fingerprint and credential-dump access rights LogSources: - Sysmon Event ID 10 (ProcessAccess) Logic: 'LSASS access with dump access mask AND CallTrace shows dbgcore/dbghelp or UNKNOWN AND source outside System32/Program Files. The triple-AND eliminates legitimate access; AV/EDR runs from Program Files with clean CallTraces. Secondary rule covers handle duplication (0x0040) from non-standard paths for HandleKatz and nanodump. Pair with companion rules for comsvcs MiniDump LOLBin (process_creation), SSP injection (image_load), and .dmp file artifacts (file_event).' ExpectedFPRate: Low UseCase: > Automated SOC alerting. Direct escalation to Tier 2/IR. If this fires, assume credential compromise and begin containment (isolate host, reset exposed credentials, check for lateral movement via pass-the-hash). SigmaRule: sigma-rules/lsass-credential-dumping/analyst.yml Intel: - Name: 'MITRE ATT&CK: T1003.001, OS Credential Dumping: LSASS Memory' Tier: primary URL: https://attack.mitre.org/techniques/T1003/001/ Description: > Primary technique definition. Documents real-world procedures by Mimikatz, ProcDump, Windows Task Manager, and comsvcs.dll. Lists mitigations including Credential Guard and PPL. - Name: 'Microsoft: Credential Guard Overview' Tier: supporting URL: https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/ Description: > Microsoft's documentation on Credential Guard (Virtualization Based Security). When deployed, isolates LSASS credential material into a separate virtual machine, preventing direct memory read attacks entirely. The chokepoint detection remains relevant for environments without Credential Guard. - Name: 'Sysmon: Event ID 10 ProcessAccess' Tier: supporting URL: https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon Description: > Sysmon documentation covering ProcessAccess event generation. Critical for understanding GrantedAccess masks, CallTrace format, and configuration requirements for LSASS monitoring. - Name: 'Fortra: Nanodump' Tier: supporting URL: https://github.com/fortra/nanodump Description: > Source code for nanodump, a minimal LSASS dumper demonstrating direct syscall, handle duplication, and process forking evasion techniques. Essential reference for understanding modern credential dump evasion and why GrantedAccess 0x0040 and UNKNOWN CallTrace patterns must be included in detection rules. RelatedChokepoints: - browser-credential-theft - edr-bypass-techniques - remote-execution-tools OsintSources: - Platform: VirusTotal Intelligence Query: 'behavior_processes:"lsass" behavior:"NtOpenProcess" tag:cred-stealer' URL: https://www.virustotal.com/gui/search/behavior_processes%3A%22lsass%22%20behavior%3A%22NtOpenProcess%22%20tag%3Acred-stealer Notes: 'Finds malware samples that access lsass.exe during sandbox execution. Pivot to the behavior tab to extract GrantedAccess patterns and dump methodology used by each sample. Cross-reference with CallTrace values to identify new evasion techniques.' - Platform: VirusTotal Intelligence Query: 'content:"sekurlsa" OR content:"MiniDumpWriteDump" OR content:"comsvcs" positives:5+' URL: https://www.virustotal.com/gui/search/content%3A%22sekurlsa%22%20OR%20content%3A%22MiniDumpWriteDump%22%20OR%20content%3A%22comsvcs%22%20positives%3A5%2B Notes: 'Finds samples containing known credential dump strings. Useful for tracking new Mimikatz variants, custom dump tools, and LOLBin abuse scripts that reference comsvcs.dll MiniDump.' - Platform: GitHub Code Search Query: '"NtOpenProcess" "lsass" language:C OR language:C++' URL: https://github.com/search?q=%22NtOpenProcess%22+%22lsass%22+language%3AC+OR+language%3AC%2B%2B&type=code Notes: 'Finds new credential dumping tool source code. Monitor for novel evasion techniques: direct syscall wrappers, handle duplication implementations, and process forking methods that may require detection rule updates.' - Platform: GitHub Code Search Query: '"MiniDumpWriteDump" "lsass" OR "sekurlsa" language:C#' URL: https://github.com/search?q=%22MiniDumpWriteDump%22+%22lsass%22+OR+%22sekurlsa%22+language%3AC%23&type=code Notes: 'Finds .NET-based credential dump tools (SharpKatz, SafetyKatz, SharpDump). These generate dbgcore.dll in CallTrace, confirming analyst rule coverage.' - Platform: LOLDrivers Query: lsass URL: https://www.loldrivers.io/ Notes: 'Database of known vulnerable kernel drivers used for BYOVD attacks. LOLDrivers has no deep-linkable query syntax; type lsass into the site search box to surface drivers with LSASS access or PPL bypass capability. PPL bypass tools (PPLBlade, PPLdump) require loading a vulnerable driver before dumping LSASS. Cross-reference with edr-bypass-techniques chokepoint for driver load detection coverage.' - Platform: ANY.RUN Query: sekurlsa URL: https://app.any.run/submissions/ Notes: 'Public submissions search takes free text only and ignores URL parameters, so the query cannot be pre-populated; search sekurlsa (then lsass, comsvcs) to find samples that interact with lsass.exe during execution. ANY.RUN provides process tree visualization showing the parent-child chain and GrantedAccess values, useful for building detection rule context.' References: - https://attack.mitre.org/techniques/T1003/001/ - https://attack.mitre.org/techniques/T1003/ - https://github.com/fortra/nanodump - https://github.com/codewhitesec/HandleKatz - https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/ - https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon - https://www.blackhillsinfosec.com/red-teamers-cookbook-byoi-bring-your-own-interpreter/ RawLogs: - Type: Sysmon EventId: 10 Source: Microsoft-Windows-Sysmon/Operational Description: 'Mimikatz-style LSASS handle acquisition: classic 0x1010 access mask from user-writable path' MatchedRules: - Research - Hunt - Analyst Sample: 'EventID: 10 (ProcessAccess) UtcTime: 2025-11-14 02:31:18.442 SourceProcessGUID: {a1b2c3d4-5e6f-7890-abcd-ef0123456789} SourceProcessId: 7284 SourceImage: C:\Users\jsmith\AppData\Local\Temp\procdump64.exe TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004} TargetProcessId: 672 TargetImage: C:\Windows\System32\lsass.exe GrantedAccess: 0x1010 CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\Windows\SYSTEM32\dbgcore.dll+6350|C:\Users\jsmith\AppData\Local\Temp\procdump64.exe+1f234 # Key signal: GrantedAccess=0x1010 (PROCESS_VM_READ | PROCESS_QUERY_INFORMATION) + TargetImage=lsass.exe # SourceImage in user-writable path with full CallTrace through dbgcore.dll indicates standard MiniDumpWriteDump flow ' - Type: Sysmon EventId: 10 Source: Microsoft-Windows-Sysmon/Operational Description: 'Direct syscall LSASS access: UNKNOWN in CallTrace indicates ntdll hook bypass' MatchedRules: - Research - Hunt - Analyst Sample: 'EventID: 10 (ProcessAccess) UtcTime: 2025-11-14 02:44:07.891 SourceProcessGUID: {a1b2c3d4-9a8b-7c6d-5e4f-3a2b1c0d9e8f} SourceProcessId: 3412 SourceImage: C:\Users\jsmith\Downloads\update.exe TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004} TargetProcessId: 672 TargetImage: C:\Windows\System32\lsass.exe GrantedAccess: 0x1FFFFF CallTrace: UNKNOWN # Key signal: CallTrace=UNKNOWN means the caller bypassed ntdll by issuing raw syscalls # High GrantedAccess (0x1FFFFF = PROCESS_ALL_ACCESS) paired with opaque CallTrace is a strong direct-syscall indicator ' - Type: Sysmon EventId: 10 Source: Microsoft-Windows-Sysmon/Operational Description: 'Handle duplication targeting LSASS: HandleKatz/nanodump evasion with GrantedAccess 0x0040' MatchedRules: - Analyst Sample: 'EventID: 10 (ProcessAccess) UtcTime: 2025-11-14 03:02:55.103 SourceProcessGUID: {a1b2c3d4-1122-3344-5566-778899aabbcc} SourceProcessId: 5890 SourceImage: C:\ProgramData\staging\svcloader.exe TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004} TargetProcessId: 672 TargetImage: C:\Windows\System32\lsass.exe GrantedAccess: 0x0040 CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\ProgramData\staging\svcloader.exe+a238 # Key signal: GrantedAccess=0x0040 (PROCESS_DUP_HANDLE) instead of classic dump access masks # Handle duplication bypasses ObRegisterCallbacks hooks that filter on PROCESS_VM_READ ' - Type: Sysmon EventId: 1 Source: Microsoft-Windows-Sysmon/Operational Description: comsvcs.dll MiniDump LOLBin, rundll32 invoking MiniDump export for LSASS dump MatchedRules: - Hunt Sample: 'EventID: 1 (Process Create) UtcTime: 2025-11-14 03:15:22.667 ProcessGuid: {a1b2c3d4-aabb-ccdd-eeff-001122334455} ProcessId: 8844 Image: C:\Windows\System32\rundll32.exe CommandLine: rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full ParentProcessGuid: {a1b2c3d4-5566-7788-99aa-bbccddeeff00} ParentProcessId: 4120 ParentImage: C:\Windows\System32\cmd.exe ParentCommandLine: cmd.exe /c rundll32.exe comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full # Key signal: rundll32.exe loading comsvcs.dll with MiniDump export and a PID argument # The PID (672) in the command line is the LSASS process ID being dumped ' TheConstant: A process must open a kernel-mediated handle to lsass.exe and read its virtual memory to extract credential material PreventionSummary: > Credential Guard and Protected Process Light (PPL) protect LSASS at the kernel level, making it significantly harder to read credential material even with admin rights. Enforcing MFA and tiered admin accounts limits the value of credentials that are dumped. PreventionOpportunities: - Category: Endpoint Control: Enable Windows Credential Guard (VBS-based LSASS protection) Impact: Moves NTLM hashes and Kerberos tickets into an isolated VBS enclave, preventing even SYSTEM-privileged processes from reading them via memory access techniques. - Category: Endpoint Control: Enable LSASS Protected Process Light (PPL) via registry or Defender for Endpoint Impact: Forces attackers to use a signed, kernel-level driver to open an LSASS handle, eliminating most usermode dump tools (Mimikatz, ProcDump, comsvcs.dll MiniDump). - Category: Identity Control: Eliminate plaintext credential exposure - disable WDigest, enforce Kerberos only for sensitive services, and rotate credentials regularly Impact: Reduces the value of dumped hashes; without NTLM or plaintext credentials, pass- the-hash and pass-the-ticket attacks are significantly constrained.