LSASS Memory

T1003.001

Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org

About this technique

Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.

As well as in-memory techniques, the LSASS process memory can be dumped from the target host and analyzed on a local system.

For example, on the target host use procdump:

* procdump -ma lsass.exe lsass_dump

Locally, mimikatz can be run using:

* sekurlsa::Minidump lsassdump.dmp
* sekurlsa::logonPasswords

Built-in Windows tools such as `comsvcs.dll` can also be used:

* rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump PID lsass.dmp full

Similar to Image File Execution Options Injection, the silent process exit mechanism can be abused to create a memory dump of `lsass.exe` through Windows Error Reporting (`WerFault.exe`).

Windows Security Support Provider (SSP) DLLs are loaded into LSASS process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored in Windows, such as any logged-on user's Domain password or smart card PINs. The SSP configuration is stored in two Registry keys: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages and HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\Security Packages. An adversary may modify these Registry keys to add new SSPs, which will be loaded the next time the system boots, or when the AddSecurityPackage Windows API function is called.

The following SSPs can be used to access credentials:

* Msv: Interactive logons, batch logons, and service logons are done through the MSV authentication package.
* Wdigest: The Digest Authentication protocol is designed for use with Hypertext Transfer Protocol (HTTP) and Simple Authentication Security Layer (SASL) exchanges.
* Kerberos: Preferred for mutual client-server domain authentication in Windows 2000 and later.
* CredSSP: Provides SSO and Network Level Authentication for Remote Desktop Services.

Detection rules88

Rules on DetectionCode tagged with T1003.001.

Sigma73

RuleLevelLog source
Antivirus - Password Dumper SignaturecriticalNULL / antivirus
HackTool - Credential Dumping Tools Named Pipe Createdcriticalwindows / pipe_created
HackTool - Dumpert Process Dumper Default Filecriticalwindows / file_event
HackTool - Dumpert Process Dumper Executioncriticalwindows / process_creation
HackTool - Inveigh Executioncriticalwindows / process_creation
HackTool - SafetyKatz Executioncriticalwindows / process_creation
HackTool - Windows Credential Editor (WCE) Executioncriticalwindows / process_creation
Potential Credential Dumping Via LSASS Process Clonecriticalwindows / process_creation
Potential Credential Dumping Via LSASS SilentProcessExit Techniquecriticalwindows / registry_event
Windows Credential Editor Registrycriticalwindows / registry_event
CreateDump Process Dumphighwindows / process_creation
Cred Dump Tools Dropped Fileshighwindows / file_event
Credential Dumping Activity By Python Based Toolhighwindows / process_access
Credential Dumping Attempt Via WerFaulthighwindows / process_access
Credential Dumping Tools Service Execution - Securityhighwindows / NULL

Splunk15

RuleTypeRiskData source
Access LSASS Memory for Dump CreationTTPNULLSysmon EventID 10
Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation ActivityTTPNULLCisco Secure Firewall Threat Defense Intrusion Event
Create Remote Thread into LSASSTTPNULLSysmon EventID 8
Creation of lsass Dump with TaskmgrTTPNULLSysmon EventID 11
Detect Credential Dumping through LSASS accessTTPNULLSysmon EventID 10
Detect Mimikatz Using Loaded ImagesTTPNULLSysmon EventID 7
Detect Mimikatz Via PowerShell And EventCode 4703TTPNULL
Dump LSASS via comsvcs DLLTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Dump LSASS via procdumpTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Dump LSASS via procdump RenameHuntingNULLSysmon EventID 1
Unsigned Image Loaded by LSASSTTPNULLSysmon EventID 7
Windows Credential Dumping LSASS Memory CreatedumpTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Hunting System Account Targeting LsassHuntingNULLSysmon EventID 10
Windows Non-System Account Targeting LsassTTPNULLSysmon EventID 10
Windows Possible Credential DumpingAnomalyNULLSysmon EventID 10

Groups44

Show 20 more

Software26

Show 2 more

Campaigns9

Procedure examples79

Groups44

Used byProcedure example
GroupAgrius

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.

GroupAPT1

APT1 has been known to use credential dumping using Mimikatz.

GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function.

GroupAPT3

APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig."

GroupAPT32

APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials.

GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials.

GroupAPT39

APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials.

GroupAPT41

APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.

View all 44 groups examples

Software26

Used byProcedure example
MalwareBad Rabbit

Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine.

MalwareCobalt Strike

Cobalt Strike can spawn a job to inject into LSASS memory and dump password hashes.

MalwareCozyCar

CozyCar has executed Mimikatz to harvest stored credentials from the victim and further victim penetration.

MalwareDaserf

Daserf leverages Mimikatz and Windows Credential Editor to steal credentials.

MalwareEmotet

Emotet has been observed dropping and executing password grabber modules including Mimikatz.

ToolEmpire

Empire contains an implementation of Mimikatz to gather credentials from memory.

MalwareGreyEnergy

GreyEnergy has a module for Mimikatz to collect Windows credentials from the victim’s machine.

ToolImpacket

SecretsDump and Mimikatz modules within Impacket can perform credential dumping to obtain account and password information.

View all 26 software examples

Campaigns9

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used Mimikatz to capture and use legitimate credentials.

Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to dump credentials utilizing LSASS.

CampaignC0032

During the C0032 campaign, TEMP.Veles used Mimikatz and a custom tool, SecHack, to harvest credentials.

CampaignCutting Edge

During Cutting Edge, threat actors used Task Manager to dump LSASS memory from Windows devices to disk.

CampaignHomeLand Justice

During HomeLand Justice, threat actors dumped LSASS memory on compromised hosts.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors targeted memory from the LSASS process to extract credentials.

CampaignOperation Wocao

During Operation Wocao, threat actors used ProcDump to dump credentials from memory.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used Mimikatz to dump LSASS memory.

View all 9 campaigns examples

References5

  1. Deep Instinct LSASS Open source
    Gilboa, A. (2021, February 16). LSASS Memory Dumps are Stealthier than Ever Before - Part 2. Retrieved December 27, 2023.
  2. Graeber 2014 Open source
    Graeber, M. (2014, October). Analysis of Malicious Security Support Provider DLLs. Retrieved March 1, 2017.
  3. Symantec Attacks Against Government Sector Open source
    Symantec. (2021, June 10). Attacks Against the Government Sector. Retrieved September 28, 2021.
  4. TechNet Blogs Credential Protection Open source
    Wilson, B. (2016, April 18). The Importance of KB2871997 and KB2928120 for Credential Protection. Retrieved April 11, 2018.
  5. Volexity Exchange Marauder March 2021 Open source
    Gruzweig, J. et al. (2021, March 2). Operation Exchange Marauder: Active Exploitation of Multiple Zero-Day Microsoft Exchange Vulnerabilities. Retrieved March 3, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.