T1003.001 LSASS Memory — ATT&CK Technique
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material. As well as in-memory techniques, the LSASS process memory can be dumped from the target host and analyzed on a local system. For example, on the target host use procdump: * procdump -ma lsass.exe lsass_dump Locally, mimikatz can be run using: * sekurlsa::Minidump lsassdump.dmp * sekurlsa::logonPasswords Built-in Windows tools such as `comsvcs.dll` can also be used: * rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump PID lsass.dmp full Similar to Image File Execution Options Injection, the silent process exit mechanism can be abused to create a memory dump of `lsass.exe` through Windows Error Reporting (`WerFault.exe`). Windows Security Support Provider (SSP) DLLs are loaded into LSASS process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs. The SSP configuration is stored in two Registry keys: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages and HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called. The following SSPs can be used to access credentials: * Msv: Interactive logons, batch logons, and service logons are done through the MSV authentication package. * Wdigest: The Digest Authentication protocol is designed for use with Hypertext Transfer Protocol (HTTP) and Simple Authentication Security Layer (SASL) exchanges. * Kerberos: Preferred for mutual client-server domain authentication in Windows 2000 and later. * CredSSP: Provides SSO and Network Level Authentication for Remote Desktop Services.
Detection coverage (50)
- Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process medium
- Potential Credential Dumping Attempt Via PowerShell medium
- Uncommon GrantedAccess Flags On LSASS medium
- LSASS Access From Program In Potentially Suspicious Folder medium
- Antivirus Password Dumper Detection critical
- PUA - Memory Dump Mount Via MemProcFS high
- Process Memory Dump via RdrLeakDiag.EXE high
- Transferring Files with Credential Data via Network Shares - Zeek medium
- LSASS Process Crashed - Application high
- Credential Dumping Tools Service Execution - Security high
- LSASS Access From Non System Account medium
- Potentially Suspicious AccessMask Requested From LSASS medium
- Password Dumper Activity on LSASS high
- Transferring Files with Credential Data via Network Shares medium
- Credential Dumping Tools Service Execution - System high
- Potential Credential Dumping Attempt Via PowerShell Remote Thread high
- Mimikatz Use high
- LSASS Access Detected via Attack Surface Reduction high
- Password Dumper Remote Thread in LSASS high
- HackTool - Impacket File Indicators high
- Cred Dump Tools Dropped Files high
- HackTool - CrackMapExec File Indicators high
- HackTool - Dumpert Process Dumper Default File critical
- HackTool - SafetyKatz Dump Indicator high
- WerFault LSASS Process Memory Dump high
- LSASS Process Memory Dump Files high
- LSASS Process Dump Artefact In CrashDumps Folder high
- LSASS Process Memory Dump Creation Via Taskmgr.EXE high
- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded high
- Time Travel Debugging Utility Usage - Image high
- Suspicious Renamed Comsvcs DLL Loaded By Rundll32 high
- Unsigned Image Loaded Into LSASS Process medium
- HackTool - Credential Dumping Tools Named Pipe Created critical
- PowerShell Get-Process LSASS in ScriptBlock high
- Lsass Memory Dump via Comsvcs DLL high
- Potential Credential Dumping Activity Via LSASS medium
- HackTool - Generic Process Access high
- Remote LSASS Process Access Through Windows Remote Management high
- Potentially Suspicious GrantedAccess Flags On LSASS medium
- HackTool - HandleKatz Duplicating LSASS Handle high
- Suspicious LSASS Access Via MalSecLogon high
- Credential Dumping Attempt Via WerFault high
- Credential Dumping Activity By Python Based Tool high
- LSASS Memory Access by Tool With Dump Keyword In Name high
- LSASS Access From Potentially White-Listed Processes high
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs high
- Potential Adplus.EXE Abuse high
- Process Access via TrolleyExpress Exclusion high
- CreateDump Process Dump high
- DumpMinitool Execution medium
Malware using this technique
- NotPetya
- Bad Rabbit
- GreyEnergy
- Emotet
- Olympic Destroyer
- Mafalda
- Okrum
- Lslsass
- Daserf
- Mimikatz
- LaZagne
- Pysa
- Cobalt Strike
- PoetRAT
- Pupy
- Qilin
- CozyCar
- Lizar
- Net Crawler
- Sliver
- SILENTTRINITY
- PowerSploit
- Windows Credential Editor
- Impacket
- Empire
- PoshC2
Threat actors using this technique
- APT41
- Evil Corp
- Void Manticore
- DragonForce
- Storm-2603
- Play Ransomware
- PLATINUM
- GALLIUM
- APT3
- Kimsuky
- Volt Typhoon
- APT32
- HAFNIUM
- MuddyWater
- FIN6
- Leafminer
- Sandworm Team
- Mustang Panda
- APT35
- APT39
- UNC3886
- OilRig
- APT27
- APT15
- APT1
- APT40
- Blue Mockingbird
- RedCurl
- MirrorFace
- Cleaver
- Medusa Ransomware
- BRONZE BUTLER
- APT33
- FIN8
- Aquatic Panda
- Ember Bear
- Whitefly
- Agrius
- APT28
- APT5
- Fox Kitten
- Earth Lusca
- Silence
- Conti
- Moonstone Sleet
- FIN13