detecting-t1003-credential-dumping-with-edr skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/detecting-t1003-credential-dumping-with-edr/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-t1003-credential-dumping-with-edr, or copy the skill folder into ~/.claude/skills/detecting-t1003-credential-dumping-with-edr/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-t1003-credential-dumping-with-edr/SKILL.md

SKILL.md (verbatim)

name: detecting-t1003-credential-dumping-with-edr
description: Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM
  database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access
  events, and Windows security event logs. Use when hunting for Mimikatz-style credential
  theft, triaging an EDR alert on LSASS access, or scoping an incident after suspected
  credential dumping.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- credential-dumping
- lsass
- mitre-t1003
- edr
- mimikatz
- ntds
- sam-database
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Token Binding
- Execution Isolation
- File Metadata Consistency Validation
- Restore Access
- Application Protocol Command Analysis
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1003.001
- T1003.002
- T1003.003
- T1003.006
mitre_f3:
  version: '1.1'
  tactics:
  - reconnaissance
  - positioning
  - initial-access
  techniques:
  - id: T1555
    name: Credentials from Password Stores
    tactic: reconnaissance
    source: attack
  - id: T1555.003
    name: 'Credentials from Password Stores: Credentials from Web Browsers'
    tactic: reconnaissance
    source: attack
  - id: T1539
    name: Steal Web Session Cookie
    tactic: positioning
    source: attack
  - id: F1006
    name: Account Takeover
    tactic: initial-access
    source: f3
  - id: F1006.002
    name: 'Account Takeover: Exposed Login Credential'
    tactic: initial-access
    source: f3

Detecting T1003 Credential Dumping with EDR

When to Use

  • When hunting for credential theft activity in the environment
  • After compromise indicators suggest attacker has elevated privileges
  • When EDR alerts fire for LSASS access or suspicious process memory reads
  • During incident response to determine scope of credential compromise
  • When auditing LSASS protection controls (Credential Guard, RunAsPPL)

Prerequisites

  • EDR agent deployed with LSASS access monitoring (CrowdStrike, Defender for Endpoint, SentinelOne)
  • Sysmon Event ID 10 (ProcessAccess) with LSASS-specific filters
  • Windows Security Event ID 4656/4663 (Object Access Auditing)
  • LSASS SACL auditing enabled (Windows 10+)
  • Registry auditing for SAM hive access

Workflow

  1. Monitor LSASS Process Access: Track all processes opening handles to lsass.exe with suspicious access rights (PROCESS_VM_READ 0x0010, PROCESS_ALL_ACCESS 0x1FFFFF). Non-privileged or unusual processes accessing LSASS are strong indicators.
  2. Detect Credential Dumping Tools: Hunt for known tool signatures -- Mimikatz (sekurlsa::logonpasswords), procdump.exe targeting LSASS, comsvcs.dll MiniDump, and Task Manager creating LSASS dumps.
  3. Monitor NTDS.dit Access: Detect Volume Shadow Copy creation (vssadmin, wmic shadowcopy) followed by NTDS.dit file access, or ntdsutil.exe IFM creation.
  4. Track SAM/SECURITY/SYSTEM Hive Access: Hunt for reg.exe save commands targeting SAM, SECURITY, and SYSTEM registry hives.
  5. Detect DCSync Activity: Monitor for non-DC accounts requesting directory replication (Event 4662 with replication GUIDs).
  6. Correlate with Lateral Movement: After credential dumping, attackers typically move laterally. Correlate credential access events with subsequent remote logon attempts.
  7. Assess Impact: Determine which credentials were potentially compromised and initiate password resets.

Key Concepts

Concept Description
T1003.001 LSASS Memory -- dumping credentials from LSASS process
T1003.002 Security Account Manager -- extracting local account hashes from SAM
T1003.003 NTDS -- extracting domain hashes from Active Directory database
T1003.004 LSA Secrets -- extracting service account passwords
T1003.005 Cached Domain Credentials -- extracting DCC2 hashes
T1003.006 DCSync -- replicating credentials from domain controller
Credential Guard Virtualization-based isolation of LSASS secrets
RunAsPPL Protected Process Light for LSASS

Detection Queries

Splunk -- LSASS Access Detection

index=sysmon EventCode=10
| where match(TargetImage, "(?i)lsass\.exe$")
| where GrantedAccess IN ("0x1FFFFF", "0x1F3FFF", "0x143A", "0x1F0FFF", "0x0040", "0x1010", "0x1410")
| where NOT match(SourceImage, "(?i)(csrss|lsass|svchost|MsMpEng|WmiPrvSE|taskmgr|procexp|SecurityHealthService)\.exe$")
| table _time Computer SourceImage SourceProcessId GrantedAccess CallTrace

Splunk -- Credential Dumping Tool Detection

index=sysmon EventCode=1
| where match(CommandLine, "(?i)(sekurlsa|lsadump|kerberos::list|crypto::certificates)")
    OR match(CommandLine, "(?i)procdump.*-ma.*lsass")
    OR match(CommandLine, "(?i)comsvcs\.dll.*MiniDump")
    OR match(CommandLine, "(?i)ntdsutil.*\"ac i ntds\".*ifm")
    OR match(CommandLine, "(?i)reg\s+save\s+hklm\\\\(sam|security|system)")
    OR match(CommandLine, "(?i)vssadmin.*create\s+shadow")
| table _time Computer User Image CommandLine ParentImage

KQL -- Microsoft Defender for Endpoint

DeviceEvents
| where Timestamp > ago(7d)
| where ActionType in ("LsassAccess", "CredentialDumpingActivity")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName,
    InitiatingProcessCommandLine, ActionType, AdditionalFields
| sort by Timestamp desc

Sigma Rule -- LSASS Credential Dumping

title: LSASS Memory Credential Dumping Attempt
status: stable
logsource:
    product: windows
    category: process_access
detection:
    selection:
        TargetImage|endswith: '\lsass.exe'
        GrantedAccess|contains:
            - '0x1FFFFF'
            - '0x1F3FFF'
            - '0x143A'
            - '0x0040'
    filter:
        SourceImage|endswith:
            - '\csrss.exe'
            - '\lsass.exe'
            - '\MsMpEng.exe'
            - '\svchost.exe'
    condition: selection and not filter
level: critical
tags:
    - attack.credential_access
    - attack.t1003.001

Common Scenarios

  1. Mimikatz sekurlsa: Direct LSASS memory reading via sekurlsa::logonpasswords to extract plaintext passwords, NTLM hashes, and Kerberos tickets.
  2. ProcDump LSASS: procdump.exe -ma lsass.exe lsass.dmp creating a memory dump for offline credential extraction.
  3. Comsvcs.dll MiniDump: rundll32.exe comsvcs.dll MiniDump [LSASS_PID] dump.bin full using a built-in Windows DLL for LSASS dumping.
  4. NTDS.dit Extraction: Creating a Volume Shadow Copy and copying NTDS.dit + SYSTEM hive for offline domain hash extraction with secretsdump.
  5. SAM Hive Export: reg save HKLM\SAM sam.save followed by reg save HKLM\SYSTEM system.save for local account hash extraction.
  6. Task Manager Dump: Right-clicking LSASS in Task Manager to create a memory dump -- a legitimate tool abused for credential theft.

Output Format

Hunt ID: TH-CRED-[DATE]-[SEQ]
Host: [Hostname]
Dumping Method: [LSASS_Access/NTDS/SAM/DCSync]
Source Process: [Tool or process used]
Target: [LSASS/NTDS.dit/SAM/SECURITY]
Access Rights: [Granted access mask]
User Context: [Account performing the dump]
ATT&CK Technique: [T1003.00x]
Risk Level: [Critical/High/Medium]
Credentials at Risk: [Scope assessment]

Other files in this skill

assets/template.md (verbatim)

T1003 Credential Dumping Hunt Template

Hunt Metadata

Field Value
Hunt ID TH-CRED-YYYY-MM-DD-NNN
Analyst
Date
Status [ ] In Progress / [ ] Complete

Hypothesis

An adversary with elevated privileges is dumping credentials from LSASS memory, SAM database, or NTDS.dit to enable lateral movement and privilege escalation.

LSASS Access Findings

# Time Host Source Process Access Mask User Severity
1

Credential Tool Detections

# Time Host Tool Command Line Technique Severity
1

Impact Assessment

  • LSASS memory potentially dumped
  • Local SAM hashes at risk
  • Domain NTDS.dit compromised
  • Service account credentials exposed
  • Kerberos tickets extracted

Recommendations

  1. Reset: [All credentials on affected systems]
  2. Enable: [Credential Guard, RunAsPPL, ASR rules]
  3. Investigate: [Lateral movement from compromised credentials]
  4. Rotate: [KRBTGT if domain-level compromise]

references/api-reference.md (verbatim)

API Reference: T1003 Credential Dumping Detection

MITRE ATT&CK T1003 Sub-Techniques

Sub-technique Name Detection
T1003.001 LSASS Memory Sysmon Event 10
T1003.002 SAM Registry Event 4688
T1003.003 NTDS.dit Event 4688, VSS events
T1003.004 LSA Secrets Registry access
T1003.005 Cached Domain Creds Registry access
T1003.006 DCSync Event 4662

Sysmon Events for Credential Dumping

Event ID 10 — ProcessAccess

Field Description
SourceProcessId PID of accessing process
SourceImage Path of accessing process
TargetProcessId PID of target (lsass.exe)
TargetImage Path of target process
GrantedAccess Access mask

Suspicious Access Masks

Mask Meaning
0x1010 QUERY_LIMITED + VM_READ
0x1FFFFF PROCESS_ALL_ACCESS
0x1410 QUERY_INFO + VM_READ
0x0040 DUP_HANDLE

Event ID 1 — ProcessCreate

<Data Name="Image">C:\tools\mimikatz.exe</Data>
<Data Name="CommandLine">mimikatz.exe "sekurlsa::logonpasswords"</Data>

Windows Security Event Log

Event 4688 — Process Creation

Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688}

Event 4662 — Object Access (DCSync detection)

Properties: {1131f6aa-9c07-11d1-f79f-00c04fc2dcd2}  # DS-Replication-Get-Changes
Properties: {1131f6ad-9c07-11d1-f79f-00c04fc2dcd2}  # DS-Replication-Get-Changes-All

CrowdStrike Falcon — Detection Query

Search for credential access alerts

GET https://api.crowdstrike.com/detects/queries/detects/v1
    ?filter=behaviors.tactic:'Credential Access'
Authorization: Bearer {token}

Microsoft Defender ATP — Advanced Hunting

LSASS Access KQL

DeviceProcessEvents
| where FileName == "lsass.exe"
| join kind=inner (
    DeviceProcessEvents
    | where InitiatingProcessFileName !in ("svchost.exe", "csrss.exe")
) on DeviceId
| project Timestamp, DeviceName, InitiatingProcessFileName

Sigma Rules

LSASS Memory Access

title: LSASS Memory Access by Non-System Process
logsource:
    product: windows
    category: process_access
detection:
    selection:
        TargetImage|endswith: '\lsass.exe'
        GrantedAccess|contains:
            - '0x1010'
            - '0x1FFFFF'
    filter:
        SourceImage|endswith:
            - '\svchost.exe'
            - '\csrss.exe'
    condition: selection and not filter
level: critical

references/standards.md (verbatim)

Standards and References - T1003 Credential Dumping Detection

MITRE ATT&CK Credential Dumping Sub-Techniques

Sub-Technique Target Common Tools Primary Detection
T1003.001 LSASS Memory Mimikatz, ProcDump, comsvcs.dll Sysmon Event 10, EDR LSASS alerts
T1003.002 SAM Database reg save, Mimikatz Registry access auditing
T1003.003 NTDS.dit ntdsutil, vssadmin, secretsdump VSS creation + file access
T1003.004 LSA Secrets Mimikatz, reg save Registry access to SECURITY hive
T1003.005 Cached Domain Creds Mimikatz, cachedump SECURITY hive access
T1003.006 DCSync Mimikatz, Impacket Event 4662 replication GUIDs

LSASS Access Masks for Credential Dumping

Access Mask Meaning Risk Level
0x1FFFFF PROCESS_ALL_ACCESS Critical
0x1F3FFF Near-full access Critical
0x143A Mimikatz typical access Critical
0x1F0FFF Full minus synchronize Critical
0x0040 PROCESS_VM_READ High
0x1010 PROCESS_VM_READ + QUERY_INFO High

Protection Controls

Control Description Effectiveness
Credential Guard Virtualizes LSASS secrets High -- prevents plaintext extraction
RunAsPPL Protected Process Light for LSASS Medium -- blocks unsigned callers
ASR Rules Attack Surface Reduction for LSASS Medium -- blocks common tools
LSASS SACL Audit logging for LSASS access Detection only
Windows Defender Credential Guard Hardware-backed isolation High

Known Credential Dumping Tools

Tool Method Detection Signature
Mimikatz Direct LSASS read via API sekurlsa::, lsadump::
ProcDump LSASS dump via MiniDumpWriteDump procdump -ma lsass
comsvcs.dll Built-in DLL MiniDump function comsvcs.dll,MiniDump
Task Manager GUI-based LSASS dump taskmgr.exe accessing lsass
ntdsutil IFM creation for NTDS "ac i ntds" "ifm"
secretsdump.py Remote NTDS extraction Impacket network activity
LaZagne Multi-source credential harvesting lazagne.exe all

references/workflows.md (verbatim)

Detailed Hunting Workflow - T1003 Credential Dumping

Phase 1: LSASS Memory Access Detection

Step 1.1 - Sysmon Event 10 Analysis

index=sysmon EventCode=10
| where match(TargetImage, "(?i)lsass\.exe$")
| where NOT match(SourceImage, "(?i)(csrss|lsass|svchost|MsMpEng|WmiPrvSE|SecurityHealthService|smartscreen)\.exe$")
| stats count values(GrantedAccess) as access_masks by SourceImage Computer
| sort -count

Step 1.2 - EDR LSASS Alerts

AlertInfo
| where Title has_any ("LSASS", "credential", "Mimikatz")
| join AlertEvidence on AlertId
| project Timestamp, Title, DeviceName, FileName, ProcessCommandLine

Phase 2: Credential Tool Detection

Step 2.1 - Known Tool Command Lines

index=sysmon EventCode=1
| where match(CommandLine, "(?i)(sekurlsa|lsadump|kerberos::list|crypto::certificates|privilege::debug)")
    OR match(OriginalFileName, "(?i)mimikatz")
    OR (match(CommandLine, "(?i)procdump") AND match(CommandLine, "(?i)lsass"))
    OR match(CommandLine, "(?i)comsvcs.*MiniDump")
| table _time Computer User Image CommandLine Hashes

Step 2.2 - NTDS.dit Extraction

index=sysmon EventCode=1
| where match(CommandLine, "(?i)(vssadmin.*create\s+shadow|wmic\s+shadowcopy|ntdsutil.*ifm|esentutl.*ntds)")
| table _time Computer User CommandLine ParentImage

Step 2.3 - Registry Hive Export

index=sysmon EventCode=1
| where match(CommandLine, "(?i)reg\s+(save|export)\s+hklm\\\\(sam|security|system)")
| table _time Computer User CommandLine

Phase 3: Post-Dump Lateral Movement

Step 3.1 - Pass-the-Hash Detection

index=wineventlog EventCode=4624 LogonType=9
| where AuthenticationPackageName="Negotiate"
| table _time TargetUserName IpAddress WorkstationName LogonProcessName

Step 3.2 - Suspicious Remote Logons After Dump

index=wineventlog EventCode=4624 LogonType=3
| where _time > [credential_dump_timestamp]
| stats count by TargetUserName IpAddress WorkstationName
| sort -count

Phase 4: Response Actions

  1. Isolate affected endpoints
  2. Reset ALL credentials that were potentially on compromised systems
  3. Rotate KRBTGT if domain-level compromise suspected
  4. Enable Credential Guard and RunAsPPL
  5. Deploy ASR rules for LSASS protection

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.