Skip to content
Threat Feed
medium advisory

Suspicious LSASS Process Access Monitoring

Detection of unauthorized handles to the Local Security Authority Subsystem Service (LSASS) process to identify potential credential dumping attempts on Windows systems.

The Local Security Authority Subsystem Service (LSASS) is a critical Windows process responsible for security policy enforcement and user authentication. Because it maintains sensitive credential material in memory, it is a primary target for adversaries seeking to escalate privileges or move laterally. This detection approach focuses on identifying unauthorized handle requests to LSASS.exe, which is a hallmark of credential dumping tools (such as those mapped to MITRE ATT&CK T1003.001).

Defenders must distinguish between malicious access and legitimate operations performed by security software, system management tools, and administrative utilities. The detection logic provides an exclusion list for common benign processes like Windows Defender, system management agents (Cisco, Oracle), and security tools (Process Explorer). Monitoring LSASS handle access provides high-value visibility into potential post-compromise credential harvesting activities.

Impact

Successful exploitation of LSASS memory allows adversaries to extract cleartext passwords, NTLM hashes, and Kerberos tickets. This compromise can lead to full administrative account takeover, facilitating lateral movement across the network and persistent, unauthorized access to sensitive corporate resources.

Recommendation

  • Enable Sysmon Event ID 10 (ProcessAccess) logging across all Windows endpoints to capture handle requests to LSASS.
  • Deploy the provided Sigma rule to detect unauthorized process access to LSASS.
  • Review the exclusion list periodically to ensure that enterprise-specific management software and legitimate security tools are not triggering false positives.
  • Use the triage guidance provided: investigate the ParentImage, GrantedAccess bits, and CallTrace in the event to differentiate between administrative automation and malicious activity.
  • Isolate endpoints where unauthorized LSASS dumping is confirmed and rotate credentials for compromised administrative accounts immediately.

Immediate actions

Enable Sysmon Event ID 10 across all Windows endpoints

IT Operations 72h

Deploy detection rule to SIEM

Detection Engineering 48h

Threat Hunt

Identify processes with unusual access rights to LSASS not covered by exclusion list

T1003.001 medium high confidence convert to detection

Data: Sysmon Event ID 10

Mitigations

Enable Credential Guard to protect LSASS memory

short_term IT Operations

Credential dumping

Detection coverage 1

Suspicious LSASS Process Access

medium

Detects unauthorized handle requests to LSASS process, potentially indicating credential dumping attempts.

sigma tactics: credential_access techniques: T1003.001 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →