Suspicious LSA secrets registry access
Identifies access to LSA secrets by suspicious processes that access sensitive SECURITY registry hives associated with cached credentials and LSA secrets storage. This behavior is commonly observed in credential dumping utilities attempting to extract plaintext secrets, service credentials, or cached domain credentials from the Local Security Authority.
- Plataforma: Windows
- Severidad: Critical
- Táctica MITRE: Acceso a credenciales
- Técnicas MITRE: T1003, T1003.004