Potential LSASS memory dump
Detects attempts to dump the LSASS process memory to disk for credential extraction. LSASS (Local Security Authority Subsystem Service) stores credential material in its process memory including NTLM hashes, Kerberos tickets. Adversaries who obtain a full or mini memory dump of LSASS process can extract these credentials offline using tools such as Mimikatz, pypykatz, or Volatility.
- Platform: Windows
- Severity: Critical
- MITRE Tactic: Credential Access
- MITRE Techniques: T1003, T1003.001