Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Credential Access

T1003.001 LSASS Memory

Sub-technique of T1003 OS Credential Dumping

Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct [Lateral…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 40.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.