<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3omicrosoftwindows/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 12:01:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3omicrosoftwindows/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Suspicious LSASS Process Access Monitoring</title><link>https://feed.craftedsignal.io/briefs/2026-10-suspicious-lsass-access/</link><pubDate>Mon, 05 Oct 2026 12:01:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-suspicious-lsass-access/</guid><description>Detection of unauthorized handles to the Local Security Authority Subsystem Service (LSASS) process to identify potential credential dumping attempts on Windows systems.</description><content:encoded><![CDATA[<p>The Local Security Authority Subsystem Service (LSASS) is a critical Windows process responsible for security policy enforcement and user authentication. Because it maintains sensitive credential material in memory, it is a primary target for adversaries seeking to escalate privileges or move laterally. This detection approach focuses on identifying unauthorized handle requests to LSASS.exe, which is a hallmark of credential dumping tools (such as those mapped to MITRE ATT&amp;CK T1003.001).</p>
<p>Defenders must distinguish between malicious access and legitimate operations performed by security software, system management tools, and administrative utilities. The detection logic provides an exclusion list for common benign processes like Windows Defender, system management agents (Cisco, Oracle), and security tools (Process Explorer). Monitoring LSASS handle access provides high-value visibility into potential post-compromise credential harvesting activities.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of LSASS memory allows adversaries to extract cleartext passwords, NTLM hashes, and Kerberos tickets. This compromise can lead to full administrative account takeover, facilitating lateral movement across the network and persistent, unauthorized access to sensitive corporate resources.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Enable Sysmon Event ID 10 (ProcessAccess) logging across all Windows endpoints to capture handle requests to LSASS.</li>
<li>Deploy the provided Sigma rule to detect unauthorized process access to LSASS.</li>
<li>Review the exclusion list periodically to ensure that enterprise-specific management software and legitimate security tools are not triggering false positives.</li>
<li>Use the triage guidance provided: investigate the ParentImage, GrantedAccess bits, and CallTrace in the event to differentiate between administrative automation and malicious activity.</li>
<li>Isolate endpoints where unauthorized LSASS dumping is confirmed and rotate credentials for compromised administrative accounts immediately.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>credential-access</category><category>windows</category><category>lsass</category><category>sysmon</category></item></channel></rss>