Suspicious LSASS Process Access Monitoring
Detection of unauthorized handles to the Local Security Authority Subsystem Service (LSASS) process to identify potential credential dumping attempts on Windows systems.
The Local Security Authority Subsystem Service (LSASS) is a critical Windows process responsible for security policy enforcement and user authentication. Because it maintains sensitive credential material in memory, it is a primary target for adversaries seeking to escalate privileges or move laterally. This detection approach focuses on identifying unauthorized handle requests to LSASS.exe, which is a hallmark of credential dumping tools (such as those mapped to MITRE ATT&CK T1003.001).
Defenders must distinguish between malicious access and legitimate operations performed by security software, system management tools, and administrative utilities. The detection logic provides an exclusion list for common benign processes like Windows Defender, system management agents (Cisco, Oracle), and security tools (Process Explorer). Monitoring LSASS handle access provides high-value visibility into potential post-compromise credential harvesting activities.
Impact
Successful exploitation of LSASS memory allows adversaries to extract cleartext passwords, NTLM hashes, and Kerberos tickets. This compromise can lead to full administrative account takeover, facilitating lateral movement across the network and persistent, unauthorized access to sensitive corporate resources.
Recommendation
- Enable Sysmon Event ID 10 (ProcessAccess) logging across all Windows endpoints to capture handle requests to LSASS.
- Deploy the provided Sigma rule to detect unauthorized process access to LSASS.
- Review the exclusion list periodically to ensure that enterprise-specific management software and legitimate security tools are not triggering false positives.
- Use the triage guidance provided: investigate the ParentImage, GrantedAccess bits, and CallTrace in the event to differentiate between administrative automation and malicious activity.
- Isolate endpoints where unauthorized LSASS dumping is confirmed and rotate credentials for compromised administrative accounts immediately.
Immediate actions
Enable Sysmon Event ID 10 across all Windows endpoints
Deploy detection rule to SIEM
Threat Hunt
Identify processes with unusual access rights to LSASS not covered by exclusion list
Data: Sysmon Event ID 10
Mitigations
Enable Credential Guard to protect LSASS memory
Credential dumping
Detection coverage 1
Suspicious LSASS Process Access
mediumDetects unauthorized handle requests to LSASS process, potentially indicating credential dumping attempts.
Detection queries are available on the platform. Get full rules →