{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/security-monitoring/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["credential-access","windows","security-monitoring"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief addresses the detection of unauthorized attempts to dump the memory contents of the Local Security Authority Subsystem Service (LSASS) process. Attackers frequently target LSASS to extract sensitive credentials, such as cleartext passwords, NTLM hashes, and Kerberos tickets, which can then be used for lateral movement and privilege escalation. Common techniques for dumping LSASS memory include the use of legitimate system tools like procdump, specialized post-exploitation frameworks like nanodump or MirrorDump, and various custom scripts. These methods often involve creating output files containing the process memory. Monitoring process creation logs for specific command-line indicators - such as filenames containing 'lsass' or extension markers like '.dmp' - allows security teams to identify and respond to credential access attempts in real-time. This detection logic is critical for identifying post-exploitation activity where attackers attempt to bypass traditional credential dumping tools that might otherwise be blocked by security software.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful dumping of LSASS memory provides attackers with the necessary credentials to escalate privileges to Domain Admin or perform lateral movement across the network. Compromised credentials can lead to full domain compromise, data exfiltration, and long-term persistence within an organization's environment. Because LSASS dumping is a precursor to further malicious actions, identifying this behavior early in the attack lifecycle is essential for limiting the blast radius of an intrusion.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for command-line arguments involving LSASS memory dump operations.\u003c/li\u003e\n\u003cli\u003eEnable Sysmon or Windows Event Log (Event ID 4688) with full command-line logging to ensure visibility into process execution.\u003c/li\u003e\n\u003cli\u003eInvestigate any triggered alerts immediately to distinguish between malicious activity and authorized administrative or diagnostic tasks.\u003c/li\u003e\n\u003cli\u003eSupplement process-based detection with memory access monitoring (e.g., using EDR telemetry) to detect direct calls to the LSASS process, as some advanced tools may avoid standard command-line indicators.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T12:45:24Z","date_published":"2026-09-03T12:45:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lsass-dump-cli-keywords/","summary":"Detection of credential access attempts targeting the Local Security Authority Subsystem Service (LSASS) process via command-line arguments indicative of memory dump creation.","title":"Detection of LSASS Memory Dumping via Command Line Keywords","url":"https://feed.craftedsignal.io/briefs/2026-09-lsass-dump-cli-keywords/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["windows","security-monitoring","informational"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief focuses on the operational visibility provided by Windows Defender's native logging capabilities, specifically regarding malware and suspicious activity detections. Security operations teams can leverage Event IDs 1006, 1015, 1116, and 1117 to identify when the antimalware engine blocks malicious files or identifies potentially unwanted programs (PUPs). Monitoring these events is essential for incident response, as they provide high-fidelity indicators that a security control has engaged to protect the endpoint. These logs facilitate the identification of compromised hosts, persistent threat attempts, and the efficacy of current defensive policies. Defenders should ingest these events to maintain situational awareness of security product triggers across the fleet.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful detection of these events allows for the rapid identification of active threats on an endpoint. If these detections are ignored, attackers may maintain persistence through obfuscated malware or bypass security controls by repeatedly attempting to execute known malicious binaries that have already been flagged by the system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rules below to your SIEM to monitor for high-confidence security triggers.\u003c/li\u003e\n\u003cli\u003eConfigure the Windows Event Log collection to capture Microsoft-Windows-Windows Defender/Operational logs.\u003c/li\u003e\n\u003cli\u003eIntegrate these detections into your automated incident response playbooks for rapid host isolation upon a confirmed malware detection (Event ID 1116).\u003c/li\u003e\n\u003cli\u003eReview the frequency of these detections per endpoint to identify systems that may be repeatedly targeted or infected, indicating a need for deeper forensic investigation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T12:35:07Z","date_published":"2026-09-03T12:35:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-windows-defender-alerts/","summary":"This brief outlines the monitoring of Windows Defender Antimalware events that indicate confirmed malware detections or suspicious system behavior.","title":"Detection of Windows Defender Malware and Suspicious Activity Events","url":"https://feed.craftedsignal.io/briefs/2026-09-windows-defender-alerts/"}],"language":"en","title":"CraftedSignal Threat Feed - Security-Monitoring","version":"https://jsonfeed.org/version/1.1"}