{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3omicrosoftwindows/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows","Cisco Secure Client","Cisco AnyConnect Secure Mobility Client","Oracle Database"],"_cs_severities":["medium"],"_cs_tags":["credential-access","windows","lsass","sysmon"],"_cs_type":"advisory","_cs_vendors":["Microsoft","Cisco","Oracle"],"content_html":"\u003cp\u003eThe Local Security Authority Subsystem Service (LSASS) is a critical Windows process responsible for security policy enforcement and user authentication. Because it maintains sensitive credential material in memory, it is a primary target for adversaries seeking to escalate privileges or move laterally. This detection approach focuses on identifying unauthorized handle requests to LSASS.exe, which is a hallmark of credential dumping tools (such as those mapped to MITRE ATT\u0026amp;CK T1003.001).\u003c/p\u003e\n\u003cp\u003eDefenders must distinguish between malicious access and legitimate operations performed by security software, system management tools, and administrative utilities. The detection logic provides an exclusion list for common benign processes like Windows Defender, system management agents (Cisco, Oracle), and security tools (Process Explorer). Monitoring LSASS handle access provides high-value visibility into potential post-compromise credential harvesting activities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of LSASS memory allows adversaries to extract cleartext passwords, NTLM hashes, and Kerberos tickets. This compromise can lead to full administrative account takeover, facilitating lateral movement across the network and persistent, unauthorized access to sensitive corporate resources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Sysmon Event ID 10 (ProcessAccess) logging across all Windows endpoints to capture handle requests to LSASS.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect unauthorized process access to LSASS.\u003c/li\u003e\n\u003cli\u003eReview the exclusion list periodically to ensure that enterprise-specific management software and legitimate security tools are not triggering false positives.\u003c/li\u003e\n\u003cli\u003eUse the triage guidance provided: investigate the ParentImage, GrantedAccess bits, and CallTrace in the event to differentiate between administrative automation and malicious activity.\u003c/li\u003e\n\u003cli\u003eIsolate endpoints where unauthorized LSASS dumping is confirmed and rotate credentials for compromised administrative accounts immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T12:01:54Z","date_published":"2026-10-05T12:01:54Z","id":"https://feed.craftedsignal.io/briefs/2026-10-suspicious-lsass-access/","summary":"Detection of unauthorized handles to the Local Security Authority Subsystem Service (LSASS) process to identify potential credential dumping attempts on Windows systems.","title":"Suspicious LSASS Process Access Monitoring","url":"https://feed.craftedsignal.io/briefs/2026-10-suspicious-lsass-access/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}