What it does. Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-t1003-credential-dumping-with-edr, or copy the skill folder into ~/.claude/skills/detecting-t1003-credential-dumping-with-edr/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-t1003-credential-dumping-with-edr/SKILL.md
SKILL.md (verbatim)
name: detecting-t1003-credential-dumping-with-edr
description: Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM
database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access
events, and Windows security event logs. Use when hunting for Mimikatz-style credential
theft, triaging an EDR alert on LSASS access, or scoping an incident after suspected
credential dumping.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- credential-dumping
- lsass
- mitre-t1003
- edr
- mimikatz
- ntds
- sam-database
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Token Binding
- Execution Isolation
- File Metadata Consistency Validation
- Restore Access
- Application Protocol Command Analysis
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1003.001
- T1003.002
- T1003.003
- T1003.006
mitre_f3:
version: '1.1'
tactics:
- reconnaissance
- positioning
- initial-access
techniques:
- id: T1555
name: Credentials from Password Stores
tactic: reconnaissance
source: attack
- id: T1555.003
name: 'Credentials from Password Stores: Credentials from Web Browsers'
tactic: reconnaissance
source: attack
- id: T1539
name: Steal Web Session Cookie
tactic: positioning
source: attack
- id: F1006
name: Account Takeover
tactic: initial-access
source: f3
- id: F1006.002
name: 'Account Takeover: Exposed Login Credential'
tactic: initial-access
source: f3
Detecting T1003 Credential Dumping with EDR
When to Use
- When hunting for credential theft activity in the environment
- After compromise indicators suggest attacker has elevated privileges
- When EDR alerts fire for LSASS access or suspicious process memory reads
- During incident response to determine scope of credential compromise
- When auditing LSASS protection controls (Credential Guard, RunAsPPL)
Prerequisites
- EDR agent deployed with LSASS access monitoring (CrowdStrike, Defender for Endpoint, SentinelOne)
- Sysmon Event ID 10 (ProcessAccess) with LSASS-specific filters
- Windows Security Event ID 4656/4663 (Object Access Auditing)
- LSASS SACL auditing enabled (Windows 10+)
- Registry auditing for SAM hive access
Workflow
- Monitor LSASS Process Access: Track all processes opening handles to lsass.exe with suspicious access rights (PROCESS_VM_READ 0x0010, PROCESS_ALL_ACCESS 0x1FFFFF). Non-privileged or unusual processes accessing LSASS are strong indicators.
- Detect Credential Dumping Tools: Hunt for known tool signatures -- Mimikatz (sekurlsa::logonpasswords), procdump.exe targeting LSASS, comsvcs.dll MiniDump, and Task Manager creating LSASS dumps.
- Monitor NTDS.dit Access: Detect Volume Shadow Copy creation (vssadmin, wmic shadowcopy) followed by NTDS.dit file access, or ntdsutil.exe IFM creation.
- Track SAM/SECURITY/SYSTEM Hive Access: Hunt for reg.exe save commands targeting SAM, SECURITY, and SYSTEM registry hives.
- Detect DCSync Activity: Monitor for non-DC accounts requesting directory replication (Event 4662 with replication GUIDs).
- Correlate with Lateral Movement: After credential dumping, attackers typically move laterally. Correlate credential access events with subsequent remote logon attempts.
- Assess Impact: Determine which credentials were potentially compromised and initiate password resets.
Key Concepts
| Concept |
Description |
| T1003.001 |
LSASS Memory -- dumping credentials from LSASS process |
| T1003.002 |
Security Account Manager -- extracting local account hashes from SAM |
| T1003.003 |
NTDS -- extracting domain hashes from Active Directory database |
| T1003.004 |
LSA Secrets -- extracting service account passwords |
| T1003.005 |
Cached Domain Credentials -- extracting DCC2 hashes |
| T1003.006 |
DCSync -- replicating credentials from domain controller |
| Credential Guard |
Virtualization-based isolation of LSASS secrets |
| RunAsPPL |
Protected Process Light for LSASS |
Detection Queries
Splunk -- LSASS Access Detection
index=sysmon EventCode=10
| where match(TargetImage, "(?i)lsass\.exe$")
| where GrantedAccess IN ("0x1FFFFF", "0x1F3FFF", "0x143A", "0x1F0FFF", "0x0040", "0x1010", "0x1410")
| where NOT match(SourceImage, "(?i)(csrss|lsass|svchost|MsMpEng|WmiPrvSE|taskmgr|procexp|SecurityHealthService)\.exe$")
| table _time Computer SourceImage SourceProcessId GrantedAccess CallTrace
index=sysmon EventCode=1
| where match(CommandLine, "(?i)(sekurlsa|lsadump|kerberos::list|crypto::certificates)")
OR match(CommandLine, "(?i)procdump.*-ma.*lsass")
OR match(CommandLine, "(?i)comsvcs\.dll.*MiniDump")
OR match(CommandLine, "(?i)ntdsutil.*\"ac i ntds\".*ifm")
OR match(CommandLine, "(?i)reg\s+save\s+hklm\\\\(sam|security|system)")
OR match(CommandLine, "(?i)vssadmin.*create\s+shadow")
| table _time Computer User Image CommandLine ParentImage
KQL -- Microsoft Defender for Endpoint
DeviceEvents
| where Timestamp > ago(7d)
| where ActionType in ("LsassAccess", "CredentialDumpingActivity")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName,
InitiatingProcessCommandLine, ActionType, AdditionalFields
| sort by Timestamp desc
Sigma Rule -- LSASS Credential Dumping
title: LSASS Memory Credential Dumping Attempt
status: stable
logsource:
product: windows
category: process_access
detection:
selection:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|contains:
- '0x1FFFFF'
- '0x1F3FFF'
- '0x143A'
- '0x0040'
filter:
SourceImage|endswith:
- '\csrss.exe'
- '\lsass.exe'
- '\MsMpEng.exe'
- '\svchost.exe'
condition: selection and not filter
level: critical
tags:
- attack.credential_access
- attack.t1003.001
Common Scenarios
- Mimikatz sekurlsa: Direct LSASS memory reading via
sekurlsa::logonpasswords to extract plaintext passwords, NTLM hashes, and Kerberos tickets.
- ProcDump LSASS:
procdump.exe -ma lsass.exe lsass.dmp creating a memory dump for offline credential extraction.
- Comsvcs.dll MiniDump:
rundll32.exe comsvcs.dll MiniDump [LSASS_PID] dump.bin full using a built-in Windows DLL for LSASS dumping.
- NTDS.dit Extraction: Creating a Volume Shadow Copy and copying NTDS.dit + SYSTEM hive for offline domain hash extraction with secretsdump.
- SAM Hive Export:
reg save HKLM\SAM sam.save followed by reg save HKLM\SYSTEM system.save for local account hash extraction.
- Task Manager Dump: Right-clicking LSASS in Task Manager to create a memory dump -- a legitimate tool abused for credential theft.
Hunt ID: TH-CRED-[DATE]-[SEQ]
Host: [Hostname]
Dumping Method: [LSASS_Access/NTDS/SAM/DCSync]
Source Process: [Tool or process used]
Target: [LSASS/NTDS.dit/SAM/SECURITY]
Access Rights: [Granted access mask]
User Context: [Account performing the dump]
ATT&CK Technique: [T1003.00x]
Risk Level: [Critical/High/Medium]
Credentials at Risk: [Scope assessment]
Other files in this skill
assets/template.md (verbatim)
T1003 Credential Dumping Hunt Template
| Field |
Value |
| Hunt ID |
TH-CRED-YYYY-MM-DD-NNN |
| Analyst |
|
| Date |
|
| Status |
[ ] In Progress / [ ] Complete |
Hypothesis
An adversary with elevated privileges is dumping credentials from LSASS memory, SAM database, or NTDS.dit to enable lateral movement and privilege escalation.
LSASS Access Findings
| # |
Time |
Host |
Source Process |
Access Mask |
User |
Severity |
| 1 |
|
|
|
|
|
|
| # |
Time |
Host |
Tool |
Command Line |
Technique |
Severity |
| 1 |
|
|
|
|
|
|
Impact Assessment
Recommendations
- Reset: [All credentials on affected systems]
- Enable: [Credential Guard, RunAsPPL, ASR rules]
- Investigate: [Lateral movement from compromised credentials]
- Rotate: [KRBTGT if domain-level compromise]
references/api-reference.md (verbatim)
API Reference: T1003 Credential Dumping Detection
MITRE ATT&CK T1003 Sub-Techniques
| Sub-technique |
Name |
Detection |
| T1003.001 |
LSASS Memory |
Sysmon Event 10 |
| T1003.002 |
SAM Registry |
Event 4688 |
| T1003.003 |
NTDS.dit |
Event 4688, VSS events |
| T1003.004 |
LSA Secrets |
Registry access |
| T1003.005 |
Cached Domain Creds |
Registry access |
| T1003.006 |
DCSync |
Event 4662 |
Sysmon Events for Credential Dumping
Event ID 10 — ProcessAccess
| Field |
Description |
| SourceProcessId |
PID of accessing process |
| SourceImage |
Path of accessing process |
| TargetProcessId |
PID of target (lsass.exe) |
| TargetImage |
Path of target process |
| GrantedAccess |
Access mask |
Suspicious Access Masks
| Mask |
Meaning |
| 0x1010 |
QUERY_LIMITED + VM_READ |
| 0x1FFFFF |
PROCESS_ALL_ACCESS |
| 0x1410 |
QUERY_INFO + VM_READ |
| 0x0040 |
DUP_HANDLE |
Event ID 1 — ProcessCreate
<Data Name="Image">C:\tools\mimikatz.exe</Data>
<Data Name="CommandLine">mimikatz.exe "sekurlsa::logonpasswords"</Data>
Windows Security Event Log
Event 4688 — Process Creation
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4688}
Event 4662 — Object Access (DCSync detection)
Properties: {1131f6aa-9c07-11d1-f79f-00c04fc2dcd2} # DS-Replication-Get-Changes
Properties: {1131f6ad-9c07-11d1-f79f-00c04fc2dcd2} # DS-Replication-Get-Changes-All
CrowdStrike Falcon — Detection Query
Search for credential access alerts
GET https://api.crowdstrike.com/detects/queries/detects/v1
?filter=behaviors.tactic:'Credential Access'
Authorization: Bearer {token}
Microsoft Defender ATP — Advanced Hunting
LSASS Access KQL
DeviceProcessEvents
| where FileName == "lsass.exe"
| join kind=inner (
DeviceProcessEvents
| where InitiatingProcessFileName !in ("svchost.exe", "csrss.exe")
) on DeviceId
| project Timestamp, DeviceName, InitiatingProcessFileName
Sigma Rules
LSASS Memory Access
title: LSASS Memory Access by Non-System Process
logsource:
product: windows
category: process_access
detection:
selection:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|contains:
- '0x1010'
- '0x1FFFFF'
filter:
SourceImage|endswith:
- '\svchost.exe'
- '\csrss.exe'
condition: selection and not filter
level: critical
references/standards.md (verbatim)
Standards and References - T1003 Credential Dumping Detection
MITRE ATT&CK Credential Dumping Sub-Techniques
| Sub-Technique |
Target |
Common Tools |
Primary Detection |
| T1003.001 |
LSASS Memory |
Mimikatz, ProcDump, comsvcs.dll |
Sysmon Event 10, EDR LSASS alerts |
| T1003.002 |
SAM Database |
reg save, Mimikatz |
Registry access auditing |
| T1003.003 |
NTDS.dit |
ntdsutil, vssadmin, secretsdump |
VSS creation + file access |
| T1003.004 |
LSA Secrets |
Mimikatz, reg save |
Registry access to SECURITY hive |
| T1003.005 |
Cached Domain Creds |
Mimikatz, cachedump |
SECURITY hive access |
| T1003.006 |
DCSync |
Mimikatz, Impacket |
Event 4662 replication GUIDs |
LSASS Access Masks for Credential Dumping
| Access Mask |
Meaning |
Risk Level |
| 0x1FFFFF |
PROCESS_ALL_ACCESS |
Critical |
| 0x1F3FFF |
Near-full access |
Critical |
| 0x143A |
Mimikatz typical access |
Critical |
| 0x1F0FFF |
Full minus synchronize |
Critical |
| 0x0040 |
PROCESS_VM_READ |
High |
| 0x1010 |
PROCESS_VM_READ + QUERY_INFO |
High |
Protection Controls
| Control |
Description |
Effectiveness |
| Credential Guard |
Virtualizes LSASS secrets |
High -- prevents plaintext extraction |
| RunAsPPL |
Protected Process Light for LSASS |
Medium -- blocks unsigned callers |
| ASR Rules |
Attack Surface Reduction for LSASS |
Medium -- blocks common tools |
| LSASS SACL |
Audit logging for LSASS access |
Detection only |
| Windows Defender Credential Guard |
Hardware-backed isolation |
High |
| Tool |
Method |
Detection Signature |
| Mimikatz |
Direct LSASS read via API |
sekurlsa::, lsadump:: |
| ProcDump |
LSASS dump via MiniDumpWriteDump |
procdump -ma lsass |
| comsvcs.dll |
Built-in DLL MiniDump function |
comsvcs.dll,MiniDump |
| Task Manager |
GUI-based LSASS dump |
taskmgr.exe accessing lsass |
| ntdsutil |
IFM creation for NTDS |
"ac i ntds" "ifm" |
| secretsdump.py |
Remote NTDS extraction |
Impacket network activity |
| LaZagne |
Multi-source credential harvesting |
lazagne.exe all |
references/workflows.md (verbatim)
Detailed Hunting Workflow - T1003 Credential Dumping
Phase 1: LSASS Memory Access Detection
Step 1.1 - Sysmon Event 10 Analysis
index=sysmon EventCode=10
| where match(TargetImage, "(?i)lsass\.exe$")
| where NOT match(SourceImage, "(?i)(csrss|lsass|svchost|MsMpEng|WmiPrvSE|SecurityHealthService|smartscreen)\.exe$")
| stats count values(GrantedAccess) as access_masks by SourceImage Computer
| sort -count
Step 1.2 - EDR LSASS Alerts
AlertInfo
| where Title has_any ("LSASS", "credential", "Mimikatz")
| join AlertEvidence on AlertId
| project Timestamp, Title, DeviceName, FileName, ProcessCommandLine
index=sysmon EventCode=1
| where match(CommandLine, "(?i)(sekurlsa|lsadump|kerberos::list|crypto::certificates|privilege::debug)")
OR match(OriginalFileName, "(?i)mimikatz")
OR (match(CommandLine, "(?i)procdump") AND match(CommandLine, "(?i)lsass"))
OR match(CommandLine, "(?i)comsvcs.*MiniDump")
| table _time Computer User Image CommandLine Hashes
index=sysmon EventCode=1
| where match(CommandLine, "(?i)(vssadmin.*create\s+shadow|wmic\s+shadowcopy|ntdsutil.*ifm|esentutl.*ntds)")
| table _time Computer User CommandLine ParentImage
Step 2.3 - Registry Hive Export
index=sysmon EventCode=1
| where match(CommandLine, "(?i)reg\s+(save|export)\s+hklm\\\\(sam|security|system)")
| table _time Computer User CommandLine
Phase 3: Post-Dump Lateral Movement
Step 3.1 - Pass-the-Hash Detection
index=wineventlog EventCode=4624 LogonType=9
| where AuthenticationPackageName="Negotiate"
| table _time TargetUserName IpAddress WorkstationName LogonProcessName
Step 3.2 - Suspicious Remote Logons After Dump
index=wineventlog EventCode=4624 LogonType=3
| where _time > [credential_dump_timestamp]
| stats count by TargetUserName IpAddress WorkstationName
| sort -count
Phase 4: Response Actions
- Isolate affected endpoints
- Reset ALL credentials that were potentially on compromised systems
- Rotate KRBTGT if domain-level compromise suspected
- Enable Credential Guard and RunAsPPL
- Deploy ASR rules for LSASS protection
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.