{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/local-security-authority-subsystem-service-lsass.exe/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Local Security Authority Subsystem Service (lsass.exe)"],"_cs_severities":["medium"],"_cs_tags":["defense-evasion","credential-access","windows","sysmon"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe Local Security Authority Subsystem Service (lsass.exe) is a core Windows process responsible for enforcing security policies and managing user credentials. Malicious actors, particularly those deploying destructive wipers like DoubleZero, often target this process to force a system shutdown, bypass security logging, or disable endpoint protection mechanisms. This brief focuses on the behavioral detection of unauthorized processes requesting the PROCESS_TERMINATE access mask (0x1) against lsass.exe. Monitoring this activity via Sysmon is critical for identifying potential data destruction attempts or sophisticated evasion techniques where an attacker seeks to cripple the host security posture.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful termination of lsass.exe on a Windows system typically results in an immediate system crash or forced reboot, leading to service disruption, potential data loss, and the disabling of security monitoring and authentication services. This technique is characteristic of destructive campaigns where the goal is to render the system inoperable or to hide subsequent malicious activities from endpoint detection solutions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Sysmon Event ID 10 across the environment with a configuration that includes monitoring for access requests to lsass.exe.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect processes requesting PROCESS_TERMINATE access.\u003c/li\u003e\n\u003cli\u003eInvestigate any process triggering this detection to identify the parent process, binary origin, and execution context.\u003c/li\u003e\n\u003cli\u003eImplement memory protection policies for core system processes where possible to prevent unauthorized handle acquisition.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T19:10:33Z","date_published":"2026-09-21T19:10:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-windows-lsass-termination/","summary":"Detection of malicious processes attempting to terminate the Local Security Authority Subsystem Service (lsass.exe) using the PROCESS_TERMINATE access mask to facilitate system instability or disable security controls.","title":"Detection of Unauthorized Lsass.exe Process Termination","url":"https://feed.craftedsignal.io/briefs/2026-09-windows-lsass-termination/"}],"language":"en","title":"CraftedSignal Threat Feed - Local Security Authority Subsystem Service (Lsass.exe)","version":"https://jsonfeed.org/version/1.1"}