1200KM / detection
T1003.001 LSASS Memory — Detection Rules
Detection workspace for T1003.001 LSASS Memory: 73 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Antivirus Password Dumper Detection · stable · critical · {"category":"antivirus"}
- Transferring Files with Credential Data via Network Shares - Zeek · test · medium · {"product":"zeek","service":"smb_files"}
- LSASS Process Crashed - Application · experimental · high · {"product":"windows","service":"application"}
- LSASS Access From Non System Account · test · medium · {"product":"windows","service":"security"}
- Credential Dumping Tools Service Execution - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Password Dumper Activity on LSASS · test · high · {"product":"windows","service":"security"}
- Potentially Suspicious AccessMask Requested From LSASS · test · medium · {"product":"windows","service":"security"}
- Transferring Files with Credential Data via Network Shares · test · medium · {"product":"windows","service":"security"}
- Credential Dumping Tools Service Execution - System · test · high · {"product":"windows","service":"system"}
- Mimikatz Use · test · high · {"product":"windows"}
- LSASS Access Detected via Attack Surface Reduction · test · high · {"product":"windows","service":"windefend","definition":"Requirements:Enabled Block credential stealing from the Windows local security authority subsystem (lsass.exe) from Attack Surface Reduction (GUID: 9e6c4e1f-7d60-472f-ba1a-a39ef669e4b2)"}
- Potential Credential Dumping Attempt Via PowerShell Remote Thread · test · high · {"product":"windows","category":"create_remote_thread"}
- Password Dumper Remote Thread in LSASS · stable · high · {"product":"windows","category":"create_remote_thread"}
- Cred Dump Tools Dropped Files · test · high · {"category":"file_event","product":"windows"}
- HackTool - CrackMapExec File Indicators · test · high · {"product":"windows","category":"file_event"}
- HackTool - Dumpert Process Dumper Default File · test · critical · {"category":"file_event","product":"windows"}
- HackTool - SafetyKatz Dump Indicator · test · high · {"category":"file_event","product":"windows"}
- HackTool - Impacket File Indicators · experimental · high · {"product":"windows","category":"file_event"}
- LSASS Process Memory Dump Files · test · high · {"product":"windows","category":"file_event"}
- LSASS Process Dump Artefact In CrashDumps Folder · test · high · {"product":"windows","category":"file_event"}
- WerFault LSASS Process Memory Dump · test · high · {"product":"windows","category":"file_event"}
- LSASS Process Memory Dump Creation Via Taskmgr.EXE · test · high · {"category":"file_event","product":"windows"}
- Suspicious Renamed Comsvcs DLL Loaded By Rundll32 · test · high · {"product":"windows","category":"image_load"}
- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded · test · high · {"category":"image_load","product":"windows"}
- Time Travel Debugging Utility Usage - Image · test · high · {"product":"windows","category":"image_load"}
- Unsigned Image Loaded Into LSASS Process · test · medium · {"category":"image_load","product":"windows"}
- HackTool - Credential Dumping Tools Named Pipe Created · test · critical · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- PowerShell Get-Process LSASS in ScriptBlock · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - Generic Process Access · test · high · {"category":"process_access","product":"windows"}
- HackTool - HandleKatz Duplicating LSASS Handle · test · high · {"category":"process_access","product":"windows"}
- Lsass Memory Dump via Comsvcs DLL · test · high · {"category":"process_access","product":"windows"}
- LSASS Memory Access by Tool With Dump Keyword In Name · test · high · {"category":"process_access","product":"windows"}
- Potential Credential Dumping Activity Via LSASS · test · medium · {"category":"process_access","product":"windows"}
- Credential Dumping Activity By Python Based Tool · stable · high · {"category":"process_access","product":"windows"}
- Remote LSASS Process Access Through Windows Remote Management · stable · high · {"category":"process_access","product":"windows"}
- Suspicious LSASS Access Via MalSecLogon · test · high · {"category":"process_access","product":"windows"}
- Potentially Suspicious GrantedAccess Flags On LSASS · test · medium · {"category":"process_access","product":"windows"}
- Credential Dumping Attempt Via WerFault · test · high · {"category":"process_access","product":"windows"}
- LSASS Access From Potentially White-Listed Processes · test · high · {"category":"process_access","product":"windows"}
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs · experimental · high · {"category":"process_access","product":"windows"}
- Potential Adplus.EXE Abuse · test · high · {"category":"process_creation","product":"windows"}
- Process Access via TrolleyExpress Exclusion · test · high · {"category":"process_creation","product":"windows"}
- CreateDump Process Dump · test · high · {"category":"process_creation","product":"windows"}
- Potential Windows Defender AV Bypass Via Dump64.EXE Rename · test · high · {"product":"windows","category":"process_creation"}
- DumpMinitool Execution · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious DumpMinitool Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - CrackMapExec Process Patterns · test · high · {"product":"windows","category":"process_creation"}
- HackTool - CreateMiniDump Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Doppelanger LSASS Dumper Execution · experimental · high · {"category":"process_creation","product":"windows"}
- HackTool - Dumpert Process Dumper Execution · test · critical · {"category":"process_creation","product":"windows"}
- HackTool - HandleKatz LSASS Dumper Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - Inveigh Execution · test · critical · {"category":"process_creation","product":"windows"}
- HackTool - Mimikatz Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - SafetyKatz Execution · test · critical · {"category":"process_creation","product":"windows"}
- HackTool - Windows Credential Editor (WCE) Execution · test · critical · {"category":"process_creation","product":"windows"}
- HackTool - WSASS Execution · experimental · high · {"category":"process_creation","product":"windows"}
- HackTool - XORDump Execution · test · high · {"category":"process_creation","product":"windows"}
- Dumping Process via Sqldumper.exe · test · medium · {"category":"process_creation","product":"windows"}
- Time Travel Debugging Utility Usage · test · high · {"product":"windows","category":"process_creation"}
- Potential Credential Dumping Via LSASS Process Clone · test · critical · {"category":"process_creation","product":"windows"}
- PUA - Memory Dump Mount Via MemProcFS · experimental · high · {"category":"process_creation","product":"windows"}
- Process Memory Dump via RdrLeakDiag.EXE · test · high · {"category":"process_creation","product":"windows"}
- Renamed CreateDump Utility Execution · test · high · {"category":"process_creation","product":"windows"}
- Process Memory Dump Via Comsvcs.DLL · test · high · {"category":"process_creation","product":"windows"}
- LSASS Dump Keyword In CommandLine · test · high · {"category":"process_creation","product":"windows"}
- Procdump Execution · test · medium · {"category":"process_creation","product":"windows"}
- Potential SysInternals ProcDump Evasion · test · high · {"category":"process_creation","product":"windows"}
- Potential LSASS Process Dump Via Procdump · stable · high · {"category":"process_creation","product":"windows"}
- Potential Credential Dumping Via WER · test · high · {"product":"windows","category":"process_creation"}
- PPL Tampering Via WerFaultSecure · experimental · high · {"category":"process_creation","product":"windows"}
- Windows Credential Editor Registry · test · critical · {"category":"registry_event","product":"windows"}
- Potential Credential Dumping Via LSASS SilentProcessExit Technique · test · critical · {"category":"registry_event","product":"windows"}
- Lsass Full Dump Request Via DumpType Registry Settings · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0363 Detection of Credential Dumping from LSASS Memory via Access and Dump Sequence
AN1030 Analytic 1030
A non-privileged or abnormal process attempts to open a handle with full access (0x1F0FFF) to lsass.exe and subsequently invokes memory dump, file creation, or registry modification indicative of credential scraping. This behavior chain reflects staged credential theft activity.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Cleaver · G0003
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- APT3 · G0022
- Threat Group-3390 · G0027
- Sandworm Team · G0034
- FIN6 · G0037
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT33 · G0064
- Leviathan · G0065
- PLATINUM · G0068
- MuddyWater · G0069
- Leafminer · G0077
- APT39 · G0087
- Silence · G0091
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Whitefly · G0107
- Blue Mockingbird · G0108
- Fox Kitten · G0117
- Indrik Spider · G0119
- HAFNIUM · G0125
- Mustang Panda · G0129
- Aquatic Panda · G0143
- Ember Bear · G1003
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- Agrius · G1030
- Moonstone Sleet · G1036
- RedCurl · G1039
- Play · G1040
- UNC3886 · G1048
- Medusa Group · G1051
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.