Files
imposterandClaude Fable 5 ad4b5c7d16 fix(osint): every pivot card links, and links execute the displayed query
Audit of the live site found 42 OSINT pivot cards: 1 real pivot with
no URL at all (aitm-websocket-relay), and 4 whose link diverged from
the query shown on the card. Policy applied: the query on the card is
exactly what the link executes; where a platform cannot express the
query, the displayed query is rewritten to the platform's real syntax.

- aitm-websocket-relay/URLScan: original query was invalid on the
  platform (page.ip.asn is not a field; filename:*.js is a rejected
  leading wildcard). Rewritten to (page.asn:AS37963 OR page.asn:AS9009)
  AND page.status:200 AND page.mimeType:"application/javascript" -
  verified live, 1583 results as of 2026-07-13 - and URL added
- lsass/LOLDrivers: site has no deep-linkable query syntax; displayed
  query is now the free-text term to type (lsass), guidance in Notes
- lsass/ANY.RUN: ?search= URL parameter is ignored by the app
  (verified live); same free-text treatment (sekurlsa)
- edr-bypass/GitHub: link now carries the full query incl. the
  (path:*.c OR path:*.asm) qualifiers; query parenthesized
- renamed-rmm/VirusTotal: link now carries all four metadata: terms,
  not just AnyDesk
- schema/chokepoint-schema.yml: document the URL field (template had
  it, schema did not - why contributors kept omitting it)

graph-api-recon-burst's N/A card is intentional (not externally
observable) and left as-is.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W87Fdr8vD1ZiR8jumj4Ud5
2026-07-13 18:34:31 -06:00

919 lines
53 KiB
YAML

Name: LSASS Credential Dumping
Id: c7df4fc6-05da-4a67-8dfa-efcd8e2420e2
MitreIds:
- T1003.001
- T1003
- T1547.005
Tactics:
- Credential Access
Techniques:
- 'OS Credential Dumping: LSASS Memory'
- OS Credential Dumping
- 'Boot or Logon Autostart Execution: Security Support Provider'
DetectionPriority: CRITICAL
ThreatPrevalence: VERY HIGH
DetectionDifficulty: MEDIUM
Description: >
To extract plaintext credentials, NTLM hashes, or Kerberos tickets from a live
Windows system, an attacker must read the memory of the Local Security Authority
Subsystem Service (lsass.exe). Windows enforces process isolation at the kernel
level: any tool that reads another process's memory must first obtain a handle via
NtOpenProcess with appropriate access rights. This kernel-mediated handle request
is the chokepoint; it fires regardless of whether the attacker uses Mimikatz,
nanodump, comsvcs.dll, ProcDump, direct syscalls, or any future tool. Even
techniques that bypass userland API hooks (ntdll unhooking, direct syscalls) still
traverse the kernel's ObRegisterCallbacks path, which Sysmon Event ID 10
(ProcessAccess) and ETW Threat Intelligence consume. The attacker cannot read
lsass memory without the kernel granting the handle.
LastUpdated: '2026-03-30'
Author: '@NovaSky0x1'
Chokepoints:
- Stage: Handle Acquisition
Input: Attacker has local admin / SYSTEM privileges on the target
Invariant: Any process must request a handle to lsass.exe with memory-read access rights from the Windows kernel.
Observable: 'Sysmon EID 10 with TargetImage=lsass.exe showing GrantedAccess and CallTrace fields'
WhyCantBypass: >
Windows enforces process isolation at the kernel level: NtOpenProcess must be
called to obtain a handle, and the kernel's ObRegisterCallbacks fires for every
handle request regardless of whether the caller used standard APIs or direct
syscalls.
LogSources:
- Sysmon Event ID 10 (ProcessAccess)
- Windows Security Event ID 4656 (Handle Requested)
- ETW Microsoft-Windows-Threat-Intelligence (kernel-level telemetry)
DetectionTier: Research
SigmaRef: sigma-rules/lsass-credential-dumping/research.yml
- Stage: Memory Read
Input: Attacker holds a valid handle to lsass.exe with memory-read rights
Invariant: The process must read lsass.exe virtual memory to extract credential material using NtReadVirtualMemory or MiniDumpWriteDump.
Observable: 'Sysmon EID 10 CallTrace showing read mechanism (dbgcore.dll, dbghelp.dll, ntdll.dll, or UNKNOWN for direct syscalls); Sysmon EID 11 if dump written to disk'
WhyCantBypass: >
Credential material (NTLM hashes, Kerberos tickets, plaintext passwords cached
by WDigest/SSP) resides in lsass.exe process memory. There is no file or
registry location that contains the same live credential state.
LogSources:
- 'Sysmon Event ID 10 (ProcessAccess: CallTrace field reveals read mechanism)'
- 'Sysmon Event ID 11 (File Create: dump file written to disk)'
DetectionTier: Hunt
SigmaRef: sigma-rules/lsass-credential-dumping/hunt.yml
BypassNote: >
Handle duplication (NtDuplicateObject) allows an attacker to clone an existing
handle to lsass from another process, producing GrantedAccess 0x0040 instead of
the standard read masks. The hunt rule includes this pattern.
- Stage: Credential Extraction
Input: Attacker has raw LSASS memory contents (live read or dump file on disk)
Invariant: The attacker must parse LSASS memory structures or dump file contents to extract usable credentials, producing observable artifacts (either an in-memory read with a suspicious CallTrace, a dump file on disk, or a DLL injected into lsass via SSP).
Observable: 'Sysmon EID 10 GrantedAccess + CallTrace correlation for live parse; Sysmon EID 7 for SSP DLL injection (ImageLoaded from non-System32 path); Sysmon EID 11 for dump file written to disk'
WhyCantBypass: >
Credential structures in lsass memory use Microsoft's internal SSP format.
The attacker must either parse them in-process (generating the ProcessAccess
event) or write a dump file for offline parsing (generating a FileCreate event).
SSP injection (loading a malicious DLL into lsass) generates an ImageLoaded
event for a DLL outside System32.
LogSources:
- 'Sysmon Event ID 10 (ProcessAccess: GrantedAccess + CallTrace correlation)'
- 'Sysmon Event ID 7 (Image Loaded: SSP DLL injection into lsass)'
- 'Sysmon Event ID 11 (File Create: dump file artifact)'
- 'Sysmon Event ID 1 (Process Creation: LOLBin execution)'
DetectionTier: Analyst
SigmaRef: sigma-rules/lsass-credential-dumping/analyst.yml
Variations:
- Name: Mimikatz (sekurlsa::logonpasswords)
FirstSeen: 2011-Q2
Status: Active
SourceURL: https://github.com/gentilkiwi/mimikatz
Notes: >
The original and most widely documented LSASS credential dumping tool. Opens
lsass.exe with PROCESS_ALL_ACCESS (0x1FFFFF) or PROCESS_VM_READ (0x1010).
Used by virtually every ransomware group and APT. GrantedAccess 0x1010 is the
classic Mimikatz fingerprint.
VariantId: mimikatz-sekurlsa
Command:
Invocation: "privilege::debug\nsekurlsa::logonpasswords\n# Or one-liner:\nmimikatz.exe \"privilege::debug\" \"sekurlsa::logonpasswords\" exit"
Context: 'Classic LSASS dumper. Opens handle with 0x1010. Used by virtually every ransomware group and APT.'
Artifacts:
- 'Sysmon EID 10: GrantedAccess 0x1010, CallTrace contains ntdll.dll'
- 'Sysmon EID 1: mimikatz.exe from non-standard path'
ChokepointMapping: 'mimikatz.exe launched → handle to lsass.exe (0x1010) → memory read → credentials extracted'
- Name: comsvcs.dll MiniDump (LOLBin)
FirstSeen: 2019-Q1
Status: Active
SourceURL: https://lolbas-project.github.io/#/OtherMSBinaries/Comsvcs
Notes: >
Living-off-the-land technique using rundll32.exe to call the MiniDump export
from comsvcs.dll (a legitimate Windows DLL). Writes a full process dump of
lsass.exe to disk. Command pattern: rundll32.exe comsvcs.dll MiniDump <pid>
<outfile> full. The MiniDump export name is a fixed Windows API; it cannot
be renamed without recompiling the DLL.
VariantId: comsvcs-minidump-lolbin
Command:
Invocation: 'rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <lsass_pid> C:\Windows\Temp\dump.dmp full'
Context: 'LOLBin technique using a legitimate Windows DLL. Microsoft-signed rundll32.exe calls the MiniDump export. Writes full LSASS dump to disk.'
Artifacts:
- 'Sysmon EID 1: rundll32.exe with comsvcs.dll and MiniDump in CommandLine'
- 'Sysmon EID 10: rundll32.exe accessing lsass.exe, CallTrace contains dbgcore.dll'
- 'Sysmon EID 11: .dmp file created in temp directory'
ChokepointMapping: 'rundll32.exe invoked → comsvcs.dll MiniDump export called → handle to lsass.exe → dump written to disk'
- Name: ProcDump (Sysinternals)
FirstSeen: 2016-Q1
Status: Active
SourceURL: https://learn.microsoft.com/en-us/sysinternals/downloads/procdump
Notes: >
Microsoft Sysinternals tool used legitimately for debugging, repurposed for
LSASS dumping. Uses MiniDumpWriteDump API (dbgcore.dll/dbghelp.dll in CallTrace).
Signed by Microsoft, so it bypasses many application whitelisting policies.
VariantId: procdump-sysinternals
Command:
Invocation: 'procdump.exe -ma lsass.exe C:\Windows\Temp\lsass.dmp'
Context: 'Microsoft Sysinternals tool. Signed by Microsoft, bypasses application whitelisting. Uses MiniDumpWriteDump API.'
Artifacts:
- 'Sysmon EID 1: procdump.exe or procdump64.exe with lsass in CommandLine'
- 'Sysmon EID 10: procdump accessing lsass.exe, CallTrace contains dbgcore.dll or dbghelp.dll'
- 'Sysmon EID 11: .dmp file created'
ChokepointMapping: 'procdump.exe launched → handle to lsass.exe → MiniDumpWriteDump called → dump file written to disk'
- Name: Nanodump
FirstSeen: 2022-Q1
Status: Active
SourceURL: https://github.com/fortra/nanodump
Notes: >
Minimal LSASS dumper designed to evade detection. Uses direct syscalls, handle
duplication, and process forking techniques. GrantedAccess patterns vary: 0x0810
for direct read, 0x0040 for handle duplication mode. Produces UNKNOWN in Sysmon
CallTrace when using direct syscalls.
VariantId: nanodump
Command:
Invocation: "nanodump.exe --write C:\\Windows\\Temp\\nano.dmp\n# Or handle duplication mode:\nnanodump.exe --dup --write C:\\Windows\\Temp\\nano.dmp\n# Or direct syscall mode:\nnanodump.exe --syscall --write C:\\Windows\\Temp\\nano.dmp"
Context: 'Minimal LSASS dumper with multiple evasion modes. Direct syscalls produce UNKNOWN in CallTrace. Handle duplication produces GrantedAccess 0x0040.'
Artifacts:
- 'Sysmon EID 10: GrantedAccess 0x0810 (direct) or 0x0040 (dup mode), CallTrace UNKNOWN for syscall mode'
- 'Sysmon EID 11: dump file (may use custom format, not standard .dmp)'
ChokepointMapping: 'nanodump launched → handle to lsass.exe (direct or duplicated) → memory read via syscall → dump written'
- Name: HandleKatz
FirstSeen: 2021-Q3
Status: Active
SourceURL: https://github.com/codewhitesec/HandleKatz
Notes: >
Abuses handle duplication to obtain a cloned handle to lsass.exe from another
process that already holds one. GrantedAccess 0x0040 (PROCESS_DUP_HANDLE).
Designed to evade detections that only look for direct PROCESS_VM_READ handles.
VariantId: handlekatz-dup
Command:
Invocation: 'handlekatz.exe --pid <lsass_pid> --outfile C:\Windows\Temp\hk.dmp'
Context: 'Clones an existing handle to lsass.exe from another process via NtDuplicateObject. Produces GrantedAccess 0x0040 instead of standard read masks.'
Artifacts:
- 'Sysmon EID 10: GrantedAccess 0x0040 (PROCESS_DUP_HANDLE) targeting lsass.exe'
- 'Sysmon EID 10: secondary handle request to the process holding the original lsass handle'
ChokepointMapping: 'handlekatz launched → finds process with existing lsass handle → NtDuplicateObject (0x0040) → memory read → credentials extracted'
- Name: PPLBlade / PPLdump
FirstSeen: 2022-Q3
Status: Active
SourceURL: https://github.com/tastypepperoni/PPLBlade
Notes: >
Bypasses Protected Process Light (PPL) protection on lsass.exe by exploiting
vulnerable signed drivers or ELAM driver abuse. Once PPL is defeated, standard
dump tools work. Detection shifts to the BYOVD/driver load stage (covered by
edr-bypass-techniques) plus the subsequent LSASS access event.
VariantId: pplblade-ppldump
Command:
Invocation: "PPLBlade.exe --mode dump --driver RTCore64.sys --output C:\\Windows\\Temp\\ppl.dmp\n# Or PPLdump:\nPPLdump.exe <lsass_pid> C:\\Windows\\Temp\\ppl.dmp"
Context: 'Two-stage attack: loads a vulnerable signed driver to disable PPL on lsass.exe, then performs standard dump. Detection shifts to the BYOVD driver load stage plus subsequent LSASS access.'
Artifacts:
- 'Sysmon EID 6: vulnerable driver loaded (RTCore64.sys, DBUtil_2_3.sys, etc.)'
- 'Sysmon EID 10: LSASS access after PPL disabled, standard access mask'
- 'Sysmon EID 11: dump file written to disk'
ChokepointMapping: 'vulnerable driver loaded (EID 6) → PPL disabled on lsass.exe → handle to lsass.exe → dump written to disk'
- Name: Task Manager Manual Dump
FirstSeen: 2014-Q1
Status: Active
Notes: >
Built-in Windows capability: right-click lsass.exe in Task Manager and select
"Create dump file." Writes a full memory dump to %TEMP%. Uses 0x1FFFFF
GrantedAccess from taskmgr.exe. Often used by less sophisticated attackers
or during hands-on-keyboard intrusions.
VariantId: task-manager-manual-dump
Command:
Invocation: 'Right-click lsass.exe in Task Manager > Create dump file'
Context: 'Built-in Windows capability. No tools required. Writes full memory dump to %TEMP%\lsass.DMP. Common in hands-on-keyboard intrusions by less sophisticated attackers.'
Artifacts:
- 'Sysmon EID 10: taskmgr.exe accessing lsass.exe with GrantedAccess 0x1FFFFF'
- 'Sysmon EID 11: lsass.DMP written to %TEMP%'
ChokepointMapping: 'taskmgr.exe opened → handle to lsass.exe (0x1FFFFF) → MiniDumpWriteDump → lsass.DMP written to %TEMP%'
- Name: SSP Injection (mimilib / memssp)
FirstSeen: 2015-Q1
Status: Active
SourceURL: https://attack.mitre.org/techniques/T1547/005/
Notes: >
Injects a malicious Security Support Provider DLL into lsass.exe via
AddSecurityPackage API or direct registry manipulation (HKLM\SYSTEM\CCS\Control\Lsa\Security Packages).
The DLL logs all future authentication events to a file. Sysmon EID 7
detects the DLL load from a non-System32 path.
VariantId: ssp-injection-mimilib
Command:
Invocation: "# Mimikatz SSP injection:\nmisc::memssp\n# Or registry-based persistence:\nreg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa /v \"Security Packages\" /t REG_MULTI_SZ /d \"mimilib\" /f"
Context: 'Injects a malicious SSP DLL into lsass.exe. Logs all future authentication events to a plaintext file. Persists across reboots via registry. Unlike other variants, this is a persistence mechanism, not a one-time dump.'
Artifacts:
- 'Sysmon EID 7: DLL loaded into lsass.exe from non-System32 path'
- 'Sysmon EID 13: registry modification to HKLM\SYSTEM\CCS\Control\Lsa\Security Packages'
- 'Sysmon EID 11: kiwissp.log or similar credential log file created'
ChokepointMapping: 'AddSecurityPackage API or registry write → malicious DLL loaded into lsass.exe (EID 7) → credentials logged to file on future authentications'
- Name: Direct Syscall Dumpers (SilentProcessExit, MirrorDump, SafetyKatz)
FirstSeen: 2020-Q2
Status: Active
SourceURL: https://github.com/GhostPack/SafetyKatz
Notes: >
Family of tools that use direct system calls (syscall stubs) to bypass ntdll.dll
userland hooks placed by EDR products. The kernel callback (ObRegisterCallbacks)
still fires, so Sysmon EID 10 still generates, but the CallTrace shows UNKNOWN
instead of ntdll.dll. MirrorDump uses DLL injection into a process with an
existing LSASS handle.
VariantId: direct-syscall-dumpers
Command:
Invocation: "# SafetyKatz (execute-assembly in C2):\nexecute-assembly SafetyKatz.exe\n# MirrorDump:\nMirrorDump.exe --output C:\\Windows\\Temp\\mirror.dmp\n# SilentProcessExit (abuse WER):\nreg add \"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SilentProcessExit\\lsass.exe\" /v ReportingMode /t REG_DWORD /d 1 /f"
Context: 'Family of tools using direct system call stubs to bypass ntdll.dll userland hooks. Kernel ObRegisterCallbacks still fires. CallTrace shows UNKNOWN instead of ntdll.dll.'
Artifacts:
- 'Sysmon EID 10: LSASS access with CallTrace containing UNKNOWN'
- 'Sysmon EID 1: suspicious process from user-writable path'
- 'Sysmon EID 11: dump file (may use non-standard format)'
ChokepointMapping: 'tool launched → direct syscall to NtOpenProcess → handle to lsass.exe (UNKNOWN CallTrace) → memory read → dump or live parse'
- Name: Pypykatz (Python)
FirstSeen: 2019-Q3
Status: Active
SourceURL: https://github.com/skelsec/pypykatz
Notes: >
Pure Python implementation of Mimikatz credential extraction. Can parse LSASS
memory dumps offline or access live LSASS via ctypes. Cross-platform, works on
Linux for parsing dump files obtained from Windows. Overlaps with BYOSI chokepoint
when Python interpreter is brought onto the target.
VariantId: pypykatz-python
Command:
Invocation: "# Live LSASS access via ctypes:\npypykatz live lsa\n# Offline dump parsing:\npypykatz lsa minidump lsass.dmp"
Context: 'Pure Python Mimikatz implementation. Can access live LSASS via ctypes or parse dump files offline. Cross-platform for offline parsing. Overlaps with BYOSI chokepoint when Python is brought onto target.'
Artifacts:
- 'Sysmon EID 10: python.exe or python3.exe accessing lsass.exe'
- 'Sysmon EID 1: python.exe running from non-standard path'
- 'Sysmon EID 3: python.exe making outbound connection (if exfiltrating)'
ChokepointMapping: 'python.exe launched → ctypes call to OpenProcess → handle to lsass.exe → memory read via ctypes → credentials parsed in-process'
- Name: Impacket secretsdump.py (Remote)
FirstSeen: 2016-Q1
Status: Active
SourceURL: https://github.com/fortra/impacket
Notes: >
Remote credential extraction over SMB. Supports multiple modes: DCSync
(replicating credentials via DRSUAPI), remote registry SAM/LSA dump, and
remote LSASS memory read via svcctl service creation. When using the LSASS
read mode, the service runs on the target and dumps locally. Overlaps with
the remote-execution-tools chokepoint for the SMB lateral movement stage.
VariantId: impacket-secretsdump
Command:
Invocation: "# Remote LSASS dump via svcctl:\nsecretsdump.py domain/user:password@target -just-dc-ntlm\n# Or with pass-the-hash:\nsecretsdump.py -hashes :NTLM_HASH domain/user@target"
Context: 'Remote credential extraction over SMB. The LSASS access event occurs on the target host via a remotely created service. Supports DCSync (DRSUAPI), remote registry SAM/LSA dump, and remote LSASS read.'
Artifacts:
- 'Sysmon EID 10: service process accessing lsass.exe on target host'
- 'Security EID 4624: network logon (Type 3) from attacker IP'
- 'Security EID 7045: new service created via svcctl'
ChokepointMapping: 'SMB authentication → svcctl service creation on target → service process handles lsass.exe → credentials extracted remotely'
- Name: CrackMapExec / NetExec (--lsa, --sam)
FirstSeen: 2019-Q2
Status: Active
SourceURL: https://github.com/Pennyw0rth/NetExec
Notes: >
Network-based credential harvesting across multiple hosts. The --lsa and
--sam flags dump credentials remotely via SMB service creation. The LSASS
access event occurs on the target host, not the attacker's machine. Used
heavily in ransomware operations for credential spraying across domains.
VariantId: crackmapexec-netexec
Command:
Invocation: "# Dump LSA secrets across multiple hosts:\nnxc smb 10.0.0.0/24 -u admin -p password --lsa\n# Dump SAM hive:\nnxc smb target -u admin -p password --sam"
Context: 'Network-based credential harvesting across multiple hosts via SMB service creation. LSASS access occurs on each target host, not the attacker machine. Used heavily in ransomware operations for domain-wide credential spraying.'
Artifacts:
- 'Sysmon EID 10: remotely created service process accessing lsass.exe on each target'
- 'Security EID 7045: new service created on each target host'
- 'Security EID 4624: network logon (Type 3) from attacker IP across multiple hosts'
ChokepointMapping: 'SMB spray across subnet → service created per host → each service handles lsass.exe → credentials collected centrally'
- Name: Cobalt Strike (logonpasswords, hashdump)
FirstSeen: 2014-Q1
Status: Active
Notes: >
Built-in beacon commands for credential theft. logonpasswords injects
Mimikatz reflectively into memory; hashdump reads the SAM hive. Both
generate Sysmon EID 10 for the LSASS access. The source process is the
beacon's host process (often rundll32.exe or a sacrificial process),
producing a non-standard source path in most deployments.
VariantId: cobalt-strike-logonpasswords
Command:
Invocation: "# Beacon commands:\nlogonpasswords\nhashdump\n# Or via execute-assembly:\nexecute-assembly /path/to/SharpKatz.exe"
Context: 'Built-in beacon commands. logonpasswords reflectively injects Mimikatz into memory. Source process is the beacon host process (often rundll32.exe or sacrificial process), producing a non-standard SourceImage in EID 10.'
Artifacts:
- 'Sysmon EID 10: beacon host process (e.g., rundll32.exe) accessing lsass.exe'
- 'Sysmon EID 1: sacrificial process spawned by beacon'
- 'Sysmon EID 8: CreateRemoteThread into lsass.exe (reflective injection)'
ChokepointMapping: 'beacon receives task → reflective Mimikatz injection or execute-assembly → handle to lsass.exe from beacon host process → credentials returned to C2'
- Name: Sliver (creds, sharp-dump)
FirstSeen: 2020-Q1
Status: Active
SourceURL: https://github.com/BishopFox/sliver
Notes: >
Open-source C2 framework from BishopFox. Supports credential dumping via
execute-assembly (loading SharpDump or SharpKatz in-process) and through
built-in BOF (Beacon Object File) execution. The LSASS access originates
from the Sliver implant process, which typically runs from a user-writable
path or injected into a legitimate process.
VariantId: sliver-creds
Command:
Invocation: "# Built-in credential dump:\ncreds\n# Or execute-assembly with SharpDump:\nexecute-assembly -t 60 SharpDump.exe\n# Or BOF execution:\nbof /path/to/nanodump.o"
Context: 'Open-source C2 from BishopFox. Credential dumping via execute-assembly (SharpDump/SharpKatz) or BOF execution. LSASS access originates from the Sliver implant process, typically running from a user-writable path or injected into a legitimate process.'
Artifacts:
- 'Sysmon EID 10: Sliver implant process accessing lsass.exe'
- 'Sysmon EID 1: implant process running from user-writable path'
- 'Sysmon EID 11: dump file if using SharpDump'
ChokepointMapping: 'Sliver implant receives task → execute-assembly or BOF loads dump tool in-process → handle to lsass.exe → credentials returned to C2'
- Name: Havoc (mimikatz, coffloader)
FirstSeen: 2022-Q3
Status: Active
SourceURL: https://github.com/HavocFramework/Havoc
Notes: >
Open-source C2 framework with built-in Mimikatz integration and COFFLoader
for executing credential dumping BOFs. The LSASS access event comes from
the Havoc demon process. Gaining popularity as a Cobalt Strike alternative
in both red team and threat actor operations.
VariantId: havoc-mimikatz
Command:
Invocation: "# Havoc demon commands:\nmimikatz\n# Or COFFLoader for BOF-based dump:\ncoffloader /path/to/nanodump.o"
Context: 'Open-source C2 with built-in Mimikatz and COFFLoader for BOFs. Gaining popularity as a Cobalt Strike alternative in both red team and threat actor operations. LSASS access comes from the Havoc demon process.'
Artifacts:
- 'Sysmon EID 10: Havoc demon process accessing lsass.exe'
- 'Sysmon EID 1: demon process, often masquerading as legitimate binary'
- 'Sysmon EID 3: demon outbound C2 connection'
ChokepointMapping: 'Havoc demon receives task → Mimikatz or BOF loaded in-process → handle to lsass.exe → credentials returned to teamserver'
- Name: Brute Ratel C4 (brc4, credstore)
FirstSeen: 2022-Q1
Status: Active
Notes: >
Commercial adversary simulation tool that has been adopted by ransomware
operators (notably BlackCat/ALPHV). Includes built-in credential harvesting
capabilities. Uses syscall-level evasion techniques similar to nanodump,
producing UNKNOWN in Sysmon CallTrace. Leaked versions circulate in
criminal forums.
VariantId: brute-ratel-credstore
Command:
Invocation: "# BRC4 badger commands:\ncredstore collect\n# Or integrated Mimikatz:\nmimikatz sekurlsa::logonpasswords"
Context: 'Commercial adversary simulation tool adopted by ransomware operators (BlackCat/ALPHV). Uses syscall-level evasion similar to nanodump, producing UNKNOWN in CallTrace. Leaked versions circulate in criminal forums.'
Artifacts:
- 'Sysmon EID 10: badger process accessing lsass.exe, CallTrace UNKNOWN'
- 'Sysmon EID 1: badger process, often injected into legitimate process'
- 'Sysmon EID 3: encrypted C2 channel'
ChokepointMapping: 'BRC4 badger receives task → syscall-level LSASS access (UNKNOWN CallTrace) → handle to lsass.exe → credentials returned to C2'
- Name: Mythic (Athena, Apollo agents)
FirstSeen: 2020-Q2
Status: Active
SourceURL: https://github.com/its-a-feature/Mythic
Notes: >
Open-source C2 platform with modular agent architecture. Credential
dumping is implemented through agent-specific modules (Athena, Apollo)
that call MiniDumpWriteDump or use direct syscalls. The source process
varies by agent configuration and injection method.
VariantId: mythic-agents
Command:
Invocation: "# Apollo agent (C#):\nmimikatz sekurlsa::logonpasswords\n# Athena agent (cross-platform):\nassembly -f SharpKatz.exe\n# Or BOF:\nbof nanodump.o"
Context: 'Open-source C2 with modular agent architecture. Credential dumping via agent-specific modules that call MiniDumpWriteDump or use direct syscalls. Source process varies by agent configuration and injection method.'
Artifacts:
- 'Sysmon EID 10: agent process accessing lsass.exe'
- 'Sysmon EID 1: agent process, varies by configuration (may be injected into legitimate process)'
- 'Sysmon EID 11: dump file if using MiniDumpWriteDump-based modules'
ChokepointMapping: 'Mythic agent receives task → credential module loaded → handle to lsass.exe → credentials returned to Mythic server'
- Name: Dumpert
FirstSeen: 2019-Q3
Status: Active
SourceURL: https://github.com/outflanknl/Dumpert
Notes: >
One of the first public tools to use direct system calls for LSASS dumping,
bypassing ntdll.dll API hooks. Calls NtOpenProcess and NtCreateFile via
syscall stubs. Produces UNKNOWN in Sysmon CallTrace. Foundational technique
adopted by nanodump and subsequent evasion tools.
VariantId: dumpert-direct-syscall
Command:
Invocation: 'Outflank-Dumpert.exe'
Context: 'One of the first public tools to use direct syscall stubs for LSASS dumping. Foundational technique adopted by nanodump and subsequent evasion tools. Calls NtOpenProcess and NtCreateFile via syscall stubs, bypassing ntdll.dll hooks.'
Artifacts:
- 'Sysmon EID 10: LSASS access with CallTrace UNKNOWN (syscall stubs bypass ntdll.dll)'
- 'Sysmon EID 1: Dumpert binary from user-writable path'
- 'Sysmon EID 11: dump file written via NtCreateFile syscall'
ChokepointMapping: 'Dumpert launched → NtOpenProcess via syscall stub (UNKNOWN CallTrace) → handle to lsass.exe → NtCreateFile writes dump to disk'
- Name: SharpKatz / SharpDump (.NET)
FirstSeen: 2019-Q1
Status: Active
SourceURL: https://github.com/GhostPack/SharpDump
Notes: >
C# implementations of credential dumping designed for execute-assembly
workflows in Cobalt Strike, Sliver, and similar frameworks. SharpKatz
reimplements Mimikatz in .NET; SharpDump creates a minidump of LSASS.
Both use MiniDumpWriteDump (dbgcore.dll in CallTrace) and run from
the beacon's process context.
VariantId: sharpkatz-sharpdump-dotnet
Command:
Invocation: "# SharpDump (minidump):\nSharpDump.exe\n# SharpKatz (in-memory parse):\nSharpKatz.exe --Command logonpasswords\n# Typically via execute-assembly in C2:\nexecute-assembly SharpDump.exe"
Context: 'C# implementations designed for execute-assembly workflows in Cobalt Strike, Sliver, and similar frameworks. Both use MiniDumpWriteDump (dbgcore.dll in CallTrace) and run from the beacon process context.'
Artifacts:
- 'Sysmon EID 10: beacon/host process accessing lsass.exe, CallTrace contains dbgcore.dll'
- 'Sysmon EID 11: .dmp file written (SharpDump writes to %TEMP% with .bin extension)'
- 'Sysmon EID 1: .NET assembly loaded in-process (no new process for execute-assembly)'
ChokepointMapping: 'execute-assembly loads .NET tool in beacon process → MiniDumpWriteDump called (dbgcore.dll in CallTrace) → handle to lsass.exe → dump written or parsed in-memory'
- Name: Out-Minidump (PowerShell)
FirstSeen: 2016-Q3
Status: Declining
SourceURL: https://github.com/PowerShellMafia/PowerSploit
Notes: >
PowerShell-based LSASS dump using .NET P/Invoke to call MiniDumpWriteDump.
Part of the PowerSploit toolkit. Generates both a PowerShell script block
log and Sysmon EID 10. Less common now due to AMSI and Script Block Logging
making PowerShell-based attacks more visible.
VariantId: out-minidump-powershell
Command:
Invocation: "# PowerSploit:\nImport-Module .\\Out-Minidump.ps1\nGet-Process lsass | Out-Minidump -DumpFilePath C:\\Windows\\Temp\\lsass.dmp"
Context: 'PowerShell-based dump using .NET P/Invoke to call MiniDumpWriteDump. Part of PowerSploit toolkit. Declining use due to AMSI and Script Block Logging making PowerShell attacks more visible.'
Artifacts:
- 'Sysmon EID 10: powershell.exe accessing lsass.exe, CallTrace contains dbgcore.dll'
- 'PowerShell Script Block Log (EID 4104): Out-Minidump function and MiniDumpWriteDump P/Invoke'
- 'Sysmon EID 11: .dmp file created'
ChokepointMapping: 'powershell.exe loads Out-Minidump → P/Invoke calls MiniDumpWriteDump → handle to lsass.exe (dbgcore.dll in CallTrace) → dump written to disk'
- Name: LSASS Shtinkering (Process Snapshotting)
FirstSeen: 2022-Q1
Status: Emerging
SourceURL: https://github.com/deepinstinct/Lsass-Shtinkering
Notes: >
Uses PssNtCaptureSnapshot to create a snapshot of the LSASS process, then
reads credentials from the snapshot instead of live memory. The snapshot
API still requires a handle to lsass.exe, so Sysmon EID 10 fires, but
the GrantedAccess mask may differ from standard dump patterns. Some EDR
products do not monitor snapshot operations.
VariantId: lsass-shtinkering-snapshot
Command:
Invocation: 'LsassShtinkering.exe --output C:\Windows\Temp\snapshot.dmp'
Context: 'Uses PssNtCaptureSnapshot to create a snapshot of LSASS, then reads credentials from the snapshot. Snapshot API still requires a handle to lsass.exe (EID 10 fires), but GrantedAccess mask may differ from standard dump patterns. Some EDR products do not monitor snapshot operations.'
Artifacts:
- 'Sysmon EID 10: process accessing lsass.exe with non-standard GrantedAccess for snapshot'
- 'Sysmon EID 1: tool binary from user-writable path'
- 'Sysmon EID 11: snapshot dump file written to disk'
ChokepointMapping: 'tool launched → PssNtCaptureSnapshot requires handle to lsass.exe (EID 10) → snapshot created → credentials parsed from snapshot'
- Name: Skeleton Key (SSP Backdoor)
FirstSeen: 2015-Q1
Status: Active
SourceURL: https://attack.mitre.org/software/S0007/
Notes: >
Variant of SSP injection that patches the LSASS authentication flow to
accept a universal "skeleton key" password for any domain account. Unlike
mimilib which logs credentials, Skeleton Key modifies authentication
in-memory. Detected via Sysmon EID 7 (DLL loaded into lsass from
non-System32 path) and anomalous Kerberos authentication patterns.
VariantId: skeleton-key-ssp
Command:
Invocation: "# Mimikatz Skeleton Key:\nmisc::skeleton\n# Patches LSASS in-memory to accept master password for any domain account"
Context: 'Patches the LSASS authentication flow to accept a universal skeleton key password. Unlike mimilib which logs credentials, Skeleton Key modifies authentication in-memory. Detected via DLL injection into lsass and anomalous Kerberos patterns.'
Artifacts:
- 'Sysmon EID 7: DLL loaded into lsass.exe from non-System32 path'
- 'Sysmon EID 10: process accessing lsass.exe for in-memory patching'
- 'Security EID 4769: anomalous Kerberos TGS requests using skeleton key'
ChokepointMapping: 'tool injects into lsass.exe (EID 7) → authentication flow patched in-memory → skeleton key password accepted for any account → detected via anomalous Kerberos patterns'
- Name: LaZagne
FirstSeen: 2015-Q1
Status: Active
SourceURL: https://github.com/AlessandroZ/LaZagne
Notes: >
Multi-platform credential harvester that extracts passwords from browsers,
databases, mail clients, Wi-Fi, and LSASS. Uses ctypes on Windows to call
OpenProcess against lsass.exe. Cross-platform (Python), often deployed
alongside BYOSI techniques.
VariantId: lazagne-multi-platform
Command:
Invocation: "# All credentials including LSASS:\nlaZagne.exe all\n# LSASS-specific:\nlaZagne.exe windows -m lsa_secrets"
Context: 'Multi-platform credential harvester. Uses ctypes on Windows to call OpenProcess against lsass.exe. Cross-platform (Python), often deployed alongside BYOSI techniques. Extracts passwords from browsers, databases, mail clients, Wi-Fi, and LSASS.'
Artifacts:
- 'Sysmon EID 10: laZagne.exe or python.exe accessing lsass.exe'
- 'Sysmon EID 1: laZagne binary or Python interpreter from user-writable path'
- 'Sysmon EID 11: credential output file if using -oN or -oJ flags'
ChokepointMapping: 'laZagne launched → OpenProcess via ctypes → handle to lsass.exe → credentials parsed from multiple sources including LSASS'
- Name: EDRSandBlast (LSASS dump mode)
FirstSeen: 2022-Q4
Status: Active
SourceURL: https://github.com/wavestone-cdt/EDRSandblast
Notes: >
Combines BYOVD driver exploitation with LSASS credential dumping in a
single tool. Loads a vulnerable driver to blind EDR kernel callbacks, then
dumps LSASS. The driver load is detectable via Sysmon EID 6 (see
edr-bypass-techniques); the LSASS access still generates EID 10 if Sysmon
kernel callbacks survive the patching attempt.
VariantId: edrsandblast-lsass
Command:
Invocation: "EDRSandblast.exe --usermode --kernelmode --dump-lsass\n# Loads vulnerable driver, patches EDR callbacks, then dumps LSASS"
Context: 'Combines BYOVD driver exploitation with LSASS dumping in a single tool. Loads a vulnerable driver to blind EDR kernel callbacks, then dumps LSASS. Two-stage detection: driver load (EID 6) then LSASS access (EID 10 if callbacks survive).'
Artifacts:
- 'Sysmon EID 6: vulnerable driver loaded (e.g., RTCore64.sys, DBUtil_2_3.sys)'
- 'Sysmon EID 10: LSASS access (if kernel callbacks survive the patching attempt)'
- 'Sysmon EID 11: dump file written to disk'
ChokepointMapping: 'vulnerable driver loaded (EID 6) → EDR kernel callbacks patched → handle to lsass.exe (EID 10 if Sysmon survives) → dump written to disk'
Prerequisites:
- The attacker must have local administrator or SYSTEM privileges on the target host (LSASS access requires SeDebugPrivilege or equivalent)
- LSASS must not be running as a Protected Process Light (PPL), or the attacker must first bypass PPL (see edr-bypass-techniques)
- Credential Guard (VBS) must not be active, or the attacker must compromise the isolated LSA environment (significantly harder, no known public tools)
- Sysmon or equivalent kernel-level telemetry must be deployed for chokepoint visibility (Security EID 4656 provides partial coverage without Sysmon)
EvolutionTimeline:
- Date: 2011-Q2
Event: Mimikatz released by Benjamin Delpy
Change: >
First publicly available tool for extracting plaintext credentials from LSASS
memory. Used PROCESS_ALL_ACCESS (0x1FFFFF) handle with standard Windows API
calls through ntdll.dll.
DetectionImpact: >
No detection existed. LSASS memory access was not monitored by any standard
Windows audit configuration. Security products relied on signature-based
detection of the Mimikatz binary itself.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2016-Q1
Event: 'LOLBin techniques emerge: ProcDump and comsvcs.dll repurposed for LSASS dumping'
Change: >
Attackers shifted from custom tools to Microsoft-signed binaries (procdump.exe,
rundll32.exe + comsvcs.dll) to bypass application whitelisting and signature
detection. The dump is written to disk for offline parsing.
DetectionImpact: >
Binary signature detection bypassed completely. Detection shifted to process
creation monitoring for known LOLBin command patterns and file creation events
for .dmp files in temp directories.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2019-Q2
Event: Sysmon EID 10 (ProcessAccess) adopted as primary LSASS monitoring source
Change: >
Microsoft Sysinternals added ProcessAccess logging to Sysmon, providing
kernel-level visibility into handle requests targeting lsass.exe. The
GrantedAccess and CallTrace fields became the foundation for behavioral
LSASS access detection independent of specific tool signatures.
DetectionImpact: >
Transformed LSASS monitoring from signature-based to behavior-based. Defenders
could now detect any tool accessing LSASS by its access mask and calling
mechanism rather than its binary name or hash.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2020-Q2
Event: Direct syscall and ntdll unhooking techniques proliferate
Change: >
Tools like SilentProcessExit, MirrorDump, and custom loaders bypass EDR
userland hooks by making system calls directly to the kernel, skipping
ntdll.dll entirely. This produces UNKNOWN in Sysmon CallTrace instead of
the standard ntdll.dll entry.
DetectionImpact: >
EDR products relying on ntdll.dll API hooks lost visibility. Sysmon EID 10
still fires because the kernel ObRegisterCallbacks mechanism operates below
the userland hook layer. UNKNOWN in CallTrace became a detection signal
rather than a blind spot.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2021-Q3
Event: Handle duplication evasion (HandleKatz, nanodump duphandle mode)
Change: >
Instead of directly opening lsass.exe, these tools open a different process
that already holds a handle to lsass, then duplicate that handle via
NtDuplicateObject. This produces GrantedAccess 0x0040 (PROCESS_DUP_HANDLE)
rather than the expected 0x1010 or 0x1FFFFF.
DetectionImpact: >
Detection rules looking only for PROCESS_VM_READ or PROCESS_ALL_ACCESS missed
the duplication pattern. Rules updated to include 0x0040 as a suspicious
GrantedAccess value when targeting lsass.exe from a non-standard source path.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2022-Q3
Event: PPL bypass tools combine BYOVD with LSASS dumping
Change: >
PPLBlade, PPLdump, and similar tools load a vulnerable signed kernel driver
to disable Protected Process Light on lsass.exe before performing the dump.
Two-stage attack: driver load (EID 6) precedes LSASS access (EID 10).
DetectionImpact: >
PPL protection is defeated before the dump occurs, so the LSASS access event
appears normal from an access-rights perspective. Detection requires
correlating the vulnerable driver load with subsequent LSASS access. See
edr-bypass-techniques for the driver load stage.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
- Date: 2024-Q3
Event: LSASS credential dumping remains universal across ransomware groups
Change: >
Kaspersky, Mandiant, and Cisco Talos reports confirm T1003.001 in 5 of 5
major ransomware families (BlackBasta, BlackCat, Akira, Qilin, LockBit).
Tool choice varies (Mimikatz, comsvcs.dll, nanodump, custom tools) but
the LSASS access event is present in every case.
DetectionImpact: >
No new evasion of the kernel-level chokepoint. Tool diversity increased but
behavioral detection via Sysmon EID 10 remained effective across all variants.
TheConstant: A process must open a handle to lsass.exe and read its virtual memory
Variants: []
EventType: event
EmulationScript:
File: emulation/lsass-credential-dumping/emulate.ps1
Language: powershell
AtomicRef: T1003.001
Description: Simulates LSASS credential dumping chokepoint stages for detection validation
SafetyNotes: >
Run in an isolated lab VM with Sysmon deployed. Requires Administrator privileges.
Does NOT extract credentials. Opens and immediately closes a handle to lsass.exe
to generate EID 10 telemetry, simulates comsvcs.dll command line for EID 1, and
creates a marker .dmp file for EID 11.
Detections:
- Level: Research
Description: Baseline all non-system processes accessing lsass.exe with memory-read permissions
LogSources:
- Sysmon Event ID 10 (ProcessAccess)
Logic: 'Any process accessing lsass.exe with credential-dump access masks
(0x1010, 0x1FFFFF, 0x1410, 0x0810, 0x0040, 0x1038, 0x1438). Filter core
OS processes only (csrss, services, svchost, lsaiso, wininit, smss,
winlogon). Everything else, including AV/EDR and WerFault, appears here.
Run for a week to build the environment-specific allowlist.'
ExpectedFPRate: High
UseCase: >
Detection engineers baselining LSASS access patterns in a new environment.
Identifies which processes normally touch LSASS to build the environment-specific
allowlist needed for Hunt and Analyst rules.
SigmaRule: sigma-rules/lsass-credential-dumping/research.yml
- Level: Hunt
Description: LSASS access with suspicious CallTrace, non-standard source path, or LOLBin dump pattern
LogSources:
- Sysmon Event ID 10 (ProcessAccess)
- Sysmon Event ID 1 (Process Creation)
Logic: 'LSASS access with credential-dump access masks AND one of: CallTrace
through dbgcore/dbghelp (MiniDumpWriteDump signature), UNKNOWN CallTrace
(direct syscall), SourceImage in a user-writable path (Temp, Downloads,
AppData, ProgramData, Users\Public), or process creation matching the
rundll32 comsvcs MiniDump or procdump LOLBin patterns. Exclude core OS
and known AV/EDR install paths.'
ExpectedFPRate: Medium
UseCase: >
Active threat hunting for credential dumping. Periodic sweeps during incident
response or campaign investigations. CallTrace analysis separates legitimate
security product access from dump tooling behavior.
SigmaRule: sigma-rules/lsass-credential-dumping/hunt.yml
- Level: Analyst
Description: Non-standard process accessing LSASS with dump mechanism fingerprint and credential-dump access rights
LogSources:
- Sysmon Event ID 10 (ProcessAccess)
Logic: 'LSASS access with dump access mask AND CallTrace shows
dbgcore/dbghelp or UNKNOWN AND source outside System32/Program Files.
The triple-AND eliminates legitimate access; AV/EDR runs from Program
Files with clean CallTraces. Secondary rule covers handle duplication
(0x0040) from non-standard paths for HandleKatz and nanodump. Pair with
companion rules for comsvcs MiniDump LOLBin (process_creation), SSP
injection (image_load), and .dmp file artifacts (file_event).'
ExpectedFPRate: Low
UseCase: >
Automated SOC alerting. Direct escalation to Tier 2/IR. If this fires,
assume credential compromise and begin containment (isolate host, reset
exposed credentials, check for lateral movement via pass-the-hash).
SigmaRule: sigma-rules/lsass-credential-dumping/analyst.yml
Intel:
- Name: 'MITRE ATT&CK: T1003.001, OS Credential Dumping: LSASS Memory'
Tier: primary
URL: https://attack.mitre.org/techniques/T1003/001/
Description: >
Primary technique definition. Documents real-world procedures by Mimikatz,
ProcDump, Windows Task Manager, and comsvcs.dll. Lists mitigations including
Credential Guard and PPL.
- Name: 'Microsoft: Credential Guard Overview'
Tier: supporting
URL: https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/
Description: >
Microsoft's documentation on Credential Guard (Virtualization Based Security).
When deployed, isolates LSASS credential material into a separate virtual
machine, preventing direct memory read attacks entirely. The chokepoint
detection remains relevant for environments without Credential Guard.
- Name: 'Sysmon: Event ID 10 ProcessAccess'
Tier: supporting
URL: https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
Description: >
Sysmon documentation covering ProcessAccess event generation. Critical for
understanding GrantedAccess masks, CallTrace format, and configuration
requirements for LSASS monitoring.
- Name: 'Fortra: Nanodump'
Tier: supporting
URL: https://github.com/fortra/nanodump
Description: >
Source code for nanodump, a minimal LSASS dumper demonstrating direct syscall,
handle duplication, and process forking evasion techniques. Essential reference
for understanding modern credential dump evasion and why GrantedAccess 0x0040
and UNKNOWN CallTrace patterns must be included in detection rules.
RelatedChokepoints:
- browser-credential-theft
- edr-bypass-techniques
- remote-execution-tools
OsintSources:
- Platform: VirusTotal Intelligence
Query: 'behavior_processes:"lsass" behavior:"NtOpenProcess" tag:cred-stealer'
URL: https://www.virustotal.com/gui/search/behavior_processes%3A%22lsass%22%20behavior%3A%22NtOpenProcess%22%20tag%3Acred-stealer
Notes: 'Finds malware samples that access lsass.exe during sandbox execution. Pivot to the behavior tab
to extract GrantedAccess patterns and dump methodology used by each sample. Cross-reference with
CallTrace values to identify new evasion techniques.'
- Platform: VirusTotal Intelligence
Query: 'content:"sekurlsa" OR content:"MiniDumpWriteDump" OR content:"comsvcs" positives:5+'
URL: https://www.virustotal.com/gui/search/content%3A%22sekurlsa%22%20OR%20content%3A%22MiniDumpWriteDump%22%20OR%20content%3A%22comsvcs%22%20positives%3A5%2B
Notes: 'Finds samples containing known credential dump strings. Useful for tracking new Mimikatz
variants, custom dump tools, and LOLBin abuse scripts that reference comsvcs.dll MiniDump.'
- Platform: GitHub Code Search
Query: '"NtOpenProcess" "lsass" language:C OR language:C++'
URL: https://github.com/search?q=%22NtOpenProcess%22+%22lsass%22+language%3AC+OR+language%3AC%2B%2B&type=code
Notes: 'Finds new credential dumping tool source code. Monitor for novel evasion techniques: direct
syscall wrappers, handle duplication implementations, and process forking methods that may require
detection rule updates.'
- Platform: GitHub Code Search
Query: '"MiniDumpWriteDump" "lsass" OR "sekurlsa" language:C#'
URL: https://github.com/search?q=%22MiniDumpWriteDump%22+%22lsass%22+OR+%22sekurlsa%22+language%3AC%23&type=code
Notes: 'Finds .NET-based credential dump tools (SharpKatz, SafetyKatz, SharpDump). These generate
dbgcore.dll in CallTrace, confirming analyst rule coverage.'
- Platform: LOLDrivers
Query: lsass
URL: https://www.loldrivers.io/
Notes: 'Database of known vulnerable kernel drivers used for BYOVD attacks. LOLDrivers has no
deep-linkable query syntax; type lsass into the site search box to surface drivers with LSASS
access or PPL bypass capability. PPL bypass tools (PPLBlade, PPLdump) require loading a
vulnerable driver before dumping LSASS. Cross-reference with edr-bypass-techniques chokepoint
for driver load detection coverage.'
- Platform: ANY.RUN
Query: sekurlsa
URL: https://app.any.run/submissions/
Notes: 'Public submissions search takes free text only and ignores URL parameters, so the query
cannot be pre-populated; search sekurlsa (then lsass, comsvcs) to find samples that interact with
lsass.exe during execution. ANY.RUN provides process tree visualization showing the parent-child
chain and GrantedAccess values, useful for building detection rule context.'
References:
- https://attack.mitre.org/techniques/T1003/001/
- https://attack.mitre.org/techniques/T1003/
- https://github.com/fortra/nanodump
- https://github.com/codewhitesec/HandleKatz
- https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/
- https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
- https://www.blackhillsinfosec.com/red-teamers-cookbook-byoi-bring-your-own-interpreter/
RawLogs:
- Type: Sysmon
EventId: 10
Source: Microsoft-Windows-Sysmon/Operational
Description: 'Mimikatz-style LSASS handle acquisition: classic 0x1010 access mask from user-writable path'
MatchedRules:
- Research
- Hunt
- Analyst
Sample: 'EventID: 10 (ProcessAccess)
UtcTime: 2025-11-14 02:31:18.442
SourceProcessGUID: {a1b2c3d4-5e6f-7890-abcd-ef0123456789}
SourceProcessId: 7284
SourceImage: C:\Users\jsmith\AppData\Local\Temp\procdump64.exe
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
TargetProcessId: 672
TargetImage: C:\Windows\System32\lsass.exe
GrantedAccess: 0x1010
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\Windows\SYSTEM32\dbgcore.dll+6350|C:\Users\jsmith\AppData\Local\Temp\procdump64.exe+1f234
# Key signal: GrantedAccess=0x1010 (PROCESS_VM_READ | PROCESS_QUERY_INFORMATION) + TargetImage=lsass.exe
# SourceImage in user-writable path with full CallTrace through dbgcore.dll indicates standard MiniDumpWriteDump flow
'
- Type: Sysmon
EventId: 10
Source: Microsoft-Windows-Sysmon/Operational
Description: 'Direct syscall LSASS access: UNKNOWN in CallTrace indicates ntdll hook bypass'
MatchedRules:
- Research
- Hunt
- Analyst
Sample: 'EventID: 10 (ProcessAccess)
UtcTime: 2025-11-14 02:44:07.891
SourceProcessGUID: {a1b2c3d4-9a8b-7c6d-5e4f-3a2b1c0d9e8f}
SourceProcessId: 3412
SourceImage: C:\Users\jsmith\Downloads\update.exe
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
TargetProcessId: 672
TargetImage: C:\Windows\System32\lsass.exe
GrantedAccess: 0x1FFFFF
CallTrace: UNKNOWN
# Key signal: CallTrace=UNKNOWN means the caller bypassed ntdll by issuing raw syscalls
# High GrantedAccess (0x1FFFFF = PROCESS_ALL_ACCESS) paired with opaque CallTrace is a strong direct-syscall indicator
'
- Type: Sysmon
EventId: 10
Source: Microsoft-Windows-Sysmon/Operational
Description: 'Handle duplication targeting LSASS: HandleKatz/nanodump evasion with GrantedAccess 0x0040'
MatchedRules:
- Analyst
Sample: 'EventID: 10 (ProcessAccess)
UtcTime: 2025-11-14 03:02:55.103
SourceProcessGUID: {a1b2c3d4-1122-3344-5566-778899aabbcc}
SourceProcessId: 5890
SourceImage: C:\ProgramData\staging\svcloader.exe
TargetProcessGUID: {a1b2c3d4-0001-0002-0003-000000000004}
TargetProcessId: 672
TargetImage: C:\Windows\System32\lsass.exe
GrantedAccess: 0x0040
CallTrace: C:\Windows\SYSTEM32\ntdll.dll+9d4c4|C:\Windows\System32\KERNELBASE.dll+2c13e|C:\ProgramData\staging\svcloader.exe+a238
# Key signal: GrantedAccess=0x0040 (PROCESS_DUP_HANDLE) instead of classic dump access masks
# Handle duplication bypasses ObRegisterCallbacks hooks that filter on PROCESS_VM_READ
'
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: comsvcs.dll MiniDump LOLBin, rundll32 invoking MiniDump export for LSASS dump
MatchedRules:
- Hunt
Sample: 'EventID: 1 (Process Create)
UtcTime: 2025-11-14 03:15:22.667
ProcessGuid: {a1b2c3d4-aabb-ccdd-eeff-001122334455}
ProcessId: 8844
Image: C:\Windows\System32\rundll32.exe
CommandLine: rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
ParentProcessGuid: {a1b2c3d4-5566-7788-99aa-bbccddeeff00}
ParentProcessId: 4120
ParentImage: C:\Windows\System32\cmd.exe
ParentCommandLine: cmd.exe /c rundll32.exe comsvcs.dll, MiniDump 672 C:\Windows\Temp\dump.dmp full
# Key signal: rundll32.exe loading comsvcs.dll with MiniDump export and a PID argument
# The PID (672) in the command line is the LSASS process ID being dumped
'
TheConstant: A process must open a kernel-mediated handle to lsass.exe and read its virtual memory to extract credential material
PreventionSummary: >
Credential Guard and Protected Process Light (PPL) protect LSASS at the kernel level,
making it significantly harder to read credential material even with admin rights.
Enforcing MFA and tiered admin accounts limits the value of credentials that are dumped.
PreventionOpportunities:
- Category: Endpoint
Control: Enable Windows Credential Guard (VBS-based LSASS protection)
Impact: Moves NTLM hashes and Kerberos tickets into an isolated VBS enclave, preventing
even SYSTEM-privileged processes from reading them via memory access techniques.
- Category: Endpoint
Control: Enable LSASS Protected Process Light (PPL) via registry or Defender for Endpoint
Impact: Forces attackers to use a signed, kernel-level driver to open an LSASS handle,
eliminating most usermode dump tools (Mimikatz, ProcDump, comsvcs.dll MiniDump).
- Category: Identity
Control: Eliminate plaintext credential exposure - disable WDigest, enforce Kerberos only
for sensitive services, and rotate credentials regularly
Impact: Reduces the value of dumped hashes; without NTLM or plaintext credentials, pass-
the-hash and pass-the-ticket attacks are significantly constrained.