logo

On Detection: Tactical to Functional

ID: 42ad6541-0900-5fb2-bb67-ec537cfc5389

STIX ID: report--42ad6541-0900-5fb2-bb67-ec537cfc5389

Feed Name: SpecterOps Blog

Date Published: 2022-08-18

Date Updated: 2026-04-30

Author: Jared Atkinson

...
...

This article formalizes an “operation graph” for OS Credential Dumping: LSASS Memory, showing that multiple operational paths—Direct Memory Access (PE → PA → PR), Handle Duplication (PE → PA → HC → PR), Process Forking (PE → PA → PC → PR), and Snapshotting (PE → PA → SsC → PR)—enable attackers to evade different defensive controls by swapping underlying function choices. By abstracting function call graphs into operations and multiplying available function entry points per operation, the author estimates 39,333 functional variations across these paths, highlighting how small tradecraft changes (e.g., NtDuplicateObject, process forks, PssCaptureSnapshot) can bypass SACL- or read-focused detections and why modeling at the operational layer improves detection strategy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.