On Detection: Tactical to Functional
ID: 42ad6541-0900-5fb2-bb67-ec537cfc5389
STIX ID: report--42ad6541-0900-5fb2-bb67-ec537cfc5389
Feed Name: SpecterOps Blog
This article formalizes an “operation graph” for OS Credential Dumping: LSASS Memory, showing that multiple operational paths—Direct Memory Access (PE → PA → PR), Handle Duplication (PE → PA → HC → PR), Process Forking (PE → PA → PC → PR), and Snapshotting (PE → PA → SsC → PR)—enable attackers to evade different defensive controls by swapping underlying function choices. By abstracting function call graphs into operations and multiplying available function entry points per operation, the author estimates 39,333 functional variations across these paths, highlighting how small tradecraft changes (e.g., NtDuplicateObject, process forks, PssCaptureSnapshot) can bypass SACL- or read-focused detections and why modeling at the operational layer improves detection strategy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
