Analytics BIOC
Medium
✕
LSASS dump file written to disk
Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Attacker's goals:
Attackers may try to extract OS credentials from the dumped Lsass.exe file.
Investigative actions:
Check the dumping process for more suspicious activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day