Potential LSASS memory dump
Detects attempts to dump the LSASS process memory to disk for credential extraction. LSASS (Local Security Authority Subsystem Service) stores credential material in its process memory including NTLM hashes, Kerberos tickets. Adversaries who obtain a full or mini memory dump of LSASS process can extract these credentials offline using tools such as Mimikatz, pypykatz, or Volatility.
- Plataforma: Windows
- Severidad: Critical
- Táctica MITRE: Acceso a credenciales
- Técnicas MITRE: T1003, T1003.001