OS Credential Dumping: LSASS Memory T1003.001
Tactic: Credential Access
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
Events covered
29 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 168 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (85 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (1419 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (405 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 90 rules
- Antivirus Password Dumper Detection
- APT31 Judgement Panda Activity
- CreateDump Process Dump
- Cred Dump Tools Dropped Files
- Credential Dumping Activity By Python Based Tool
- Credential Dumping Attempt Via WerFault
- Credential Dumping Tools Service Execution - Security
- Credential Dumping Tools Service Execution - System
- Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process
- Dumping Process via Sqldumper.exe
- DumpMinitool Execution
- HackTool - CrackMapExec File Indicators
- HackTool - CrackMapExec Process Patterns
- HackTool - CreateMiniDump Execution
- HackTool - Credential Dumping Tools Named Pipe Created
- HackTool - Doppelanger LSASS Dumper Execution
- HackTool - Dumpert Process Dumper Default File
- HackTool - Dumpert Process Dumper Execution
- HackTool - Generic Process Access
- HackTool - HandleKatz Duplicating LSASS Handle
- HackTool - HandleKatz LSASS Dumper Execution
- HackTool - Impacket File Indicators
- HackTool - Inveigh Execution
- HackTool - Mimikatz Execution
- HackTool - SafetyKatz Dump Indicator
- HackTool - SafetyKatz Execution
- HackTool - Windows Credential Editor (WCE) Execution
- HackTool - WSASS Execution
- HackTool - XORDump Execution
- LSASS Access Detected via Attack Surface Reduction
- LSASS Access From Non System Account
- LSASS Access From Potentially White-Listed Processes
- LSASS Access From Program In Potentially Suspicious Folder
- LSASS credential dump with LSASSY (admin share)
- LSASS credential dump with LSASSY (kernel access)
- LSASS credential dump with LSASSY (PowerShell)
- LSASS credential dump with LSASSY (process)
- LSASS credentials dump via Task Manager (file)
- LSASS Dump Keyword In CommandLine
- LSASS dump via process access
- Lsass Full Dump Request Via DumpType Registry Settings
- LSASS Memory Access by Tool With Dump Keyword In Name
- Lsass Memory Dump via Comsvcs DLL
- LSASS Process Crashed - Application
- LSASS Process Dump Artefact In CrashDumps Folder
- LSASS process dump by a non system account
- LSASS Process Memory Dump Creation Via Taskmgr.EXE
- LSASS Process Memory Dump Files
- Mimikatz Use
- NotPetya Ransomware Activity
- Password Dumper Activity on LSASS
- Password Dumper Remote Thread in LSASS
- Potential Adplus.EXE Abuse
- Potential Credential Dumping Activity Via LSASS
- Potential Credential Dumping Attempt Via PowerShell
- Potential Credential Dumping Attempt Via PowerShell Remote Thread
- Potential Credential Dumping Via LSASS Process Clone
- Potential Credential Dumping Via LSASS SilentProcessExit Technique
- Potential Credential Dumping Via WER
- Potential LSASS Process Dump Via Procdump
- Potential SAM database user credentials dumped with DCshadow
- Potential SysInternals ProcDump Evasion
- Potential Windows Defender AV Bypass Via Dump64.EXE Rename
- Potentially Suspicious AccessMask Requested From LSASS
- Potentially Suspicious GrantedAccess Flags On LSASS
- PowerShell Get-Process LSASS in ScriptBlock
- PPL Tampering Via WerFaultSecure
- Procdump Execution
- Process Access via TrolleyExpress Exclusion
- Process Memory Dump Via Comsvcs.DLL
- Process Memory Dump via RdrLeakDiag.EXE
- PUA - Memory Dump Mount Via MemProcFS
- Remote LSASS Process Access Through Windows Remote Management
- Renamed CreateDump Utility Execution
- SAM database user credentials dump with Mimikatz
- Suspicious DumpMinitool Execution
- Suspicious LSASS Access Via MalSecLogon
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
- Suspicious Renamed Comsvcs DLL Loaded By Rundll32
- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded
- Task Manager access indicator for potential LSASS dump
- Task Manager used for LSASS dump (kernel)
- Time Travel Debugging Utility Usage
- Time Travel Debugging Utility Usage - Image
- Transferring Files with Credential Data via Network Shares
- Transferring Files with Credential Data via Network Shares - Zeek
- Uncommon GrantedAccess Flags On LSASS
- Unsigned Image Loaded Into LSASS Process
- WerFault LSASS Process Memory Dump
- Windows Credential Editor Registry
Elastic 23 rules
- Credential Dumping - Detected - Elastic Endgame
- Credential Dumping - Prevented - Elastic Endgame
- Disabling Lsa Protection via Registry Modification
- Full User-Mode Dumps Enabled System-Wide
- LSASS Memory Dump Creation
- LSASS Memory Dump Handle Access
- LSASS Process Access via Windows API
- Memory Dump File with Unusual Extension
- Modification of WDigest Security Provider
- Potential Credential Access via DuplicateHandle in LSASS
- Potential Credential Access via LSASS Memory Dump
- Potential Credential Access via Memory Dump File Creation
- Potential Credential Access via Renamed COM+ Services DLL
- Potential Credential Access via Windows Utilities
- Potential Invoke-Mimikatz PowerShell Script
- Potential LSASS Clone Creation via PssCaptureSnapShot
- Potential LSASS Memory Dump via PssCaptureSnapShot
- Potential PowerShell HackTool Script by Function Names
- PowerShell Kerberos Ticket Dump
- PowerShell MiniDump Script
- Suspicious LSASS Access via MalSecLogon
- Suspicious Lsass Process Access
- Suspicious Module Loaded by LSASS
Splunk 26 rules
- Access LSASS Memory for Dump Creation
- Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity
- Common LSASS Memory Dump Behavior (Windows Event Log)
- comsvcs.dll Lsass Memory Dump (Sysmon)
- comsvcs.dll Lsass Memory Dump (Windows Event Log)
- Create Remote Thread into LSASS
- Creation of lsass Dump with Taskmgr
- Detect Credential Dumping through LSASS access
- Dump LSASS via comsvcs DLL
- Dump LSASS via procdump
- LSASS Handle request (Windows Event Log)
- Mimikatz (Sysmon)
- Mimikatz (Windows Event Log)
- MultiDump.exe Execution (Sysmon)
- MultiDump.exe Execution (Windows Event Log)
- ProcDump Credential Harvest (Sysmon)
- ProcDump Credential Harvest (Windows Event Log)
- pypykatz commands (Windows Event Log)
- RdrLeakDiag.exe Memory Dump (PowerShell)
- RdrLeakDiag.exe Memory Dump (Sysmon)
- RdrLeakDiag.exe Memory Dump (Windows Event Log)
- Task Manager lsass Dump (Windows Event Log)
- Windows Credential Dumping LSASS Memory Createdump
- Windows Hunting System Account Targeting Lsass
- Windows Non-System Account Targeting Lsass
- Windows Possible Credential Dumping
Kusto 8 rules
- Alsid LSASS Memory
- Credential Dumping Tools - File Artifacts
- Credential Dumping Tools - Service Installation
- Dumping LSASS Process Into a File
- LSASS Dumping using Debug Privileges
- Powershell Empire Cmdlets Executed in Command Line
- Tenable.ad LSASS Memory
- TIE LSASS Memory
YARA-L 18 rules
- CreateDump Process Dump
- Cred Dump Tools Dropped Files
- Credential Dumping Attempt Via WerFault
- HackTool - Dumpert Process Dumper Default File
- HackTool - Dumpert Process Dumper Execution
- HackTool - Generic Process Access
- HackTool - Mimikatz Execution
- LSASS Dump Keyword In CommandLine
- LSASS Memory Access by Tool With Dump Keyword In Name
- Lsass Memory Dump via Comsvcs DLL
- LSASS Process Memory Dump Creation Via Taskmgr.exe
- LSASS Process Memory Dump Files
- Potential Credential Dumping Activity Via LSASS
- Potential Credential Dumping Via LSASS SilentProcessExit Technique
- potential lsass process dump via procdump
- Process Memory Dump Via Comsvcs.DLL
- Process Memory Dump via RdrLeakDiag.exe
- Renamed CreateDump Utility Execution