mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
New chokepoint covering the kernel-mediated handle request to lsass.exe, the invariant prerequisite for all credential dumping tools. - Chokepoint YAML with 3 stages, 24 variations, 7 evolution timeline entries - Research sigma rule: baseline all non-system LSASS access (process_access) - Hunt sigma rule: CallTrace + source path behavioral filtering - Analyst sigma rule: triple-AND (access mask + dump mechanism + non-standard path) - Emulation script with SeDebugPrivilege handling and PPL detection - 4 raw log samples, 6 OSINT pivots, CHANGELOG updated