1200KM / simulation
T1003.001 LSASS Memory — Attack Simulation
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material. As well as in-memory techniques,…
Technique description
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material. As well as in-memory techniques,…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Dump LSASS.exe Memory using ProcDump
Procedure 0be2230c-9ab3-4ac2-8826-3199b9a0ebf8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dump LSASS.exe Memory using comsvcs.dll
Procedure 2536dee2-12fb-459a-8c37-971844fa73be; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Offline Credential Theft With Mimikatz
Procedure 453acf13-1dbd-47d7-b28a-172ce9228023; elevation required; cleanup not declared. Not executed or individually validated.
- Dump LSASS.exe using lolbin rdrleakdiag.exe
Procedure 47a539d1-61b9-4364-bf49-a68bc2a95ef0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dump LSASS.exe Memory using Out-Minidump.ps1
Procedure 6502c8f0-b775-4dbd-9193-1298f56b6781; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Powershell Mimikatz
Procedure 66fb0bc1-3c3f-47e9-a298-550ecfefacbc; elevation required; cleanup not declared. Not executed or individually validated.
- Dump LSASS.exe Memory using direct system calls and API unhooking
Procedure 7ae7102c-a099-45c8-b985-4c7a2d05790d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create Mini Dump of LSASS.exe using ProcDump
Procedure 7cede33f-0acd-44ef-9774-15511300b24b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dump LSASS.exe using imported Microsoft DLLs
Procedure 86fc3f40-237f-4701-b155-81c01c48d697; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dump LSASS with createdump.exe from .Net v5
Procedure 9d0072c8-7cca-45c4-bd14-f852cfa35cf0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- LSASS read with pypykatz
Procedure c37bc535-5c62-4195-9cc3-0517673171d8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dump LSASS.exe Memory using NanoDump
Procedure dddd4aca-bbed-46f0-984d-e4c5971c51ea; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dump LSASS.exe Memory using Windows Task Manager
Procedure dea6c349-f1c6-44f3-87a1-1ed33a59a607; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Dump LSASS.exe Memory through Silent Process Exit
Procedure eb5adf16-b601-4926-bca7-dad22adffb37; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Cleaver · G0003
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- APT3 · G0022
- Threat Group-3390 · G0027
- Sandworm Team · G0034
- FIN6 · G0037
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT33 · G0064
- Leviathan · G0065
- PLATINUM · G0068
- MuddyWater · G0069
- Leafminer · G0077
- APT39 · G0087
- Silence · G0091
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Whitefly · G0107
- Blue Mockingbird · G0108
- Fox Kitten · G0117
- Indrik Spider · G0119
- HAFNIUM · G0125
- Mustang Panda · G0129
- Aquatic Panda · G0143
- Ember Bear · G1003
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- APT5 · G1023
- Agrius · G1030
- Moonstone Sleet · G1036
- RedCurl · G1039
- Play · G1040
- UNC3886 · G1048
- Medusa Group · G1051
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.