logo

Ghost in LSASS: Detecting KslKatz Credential Dumping Framework

ID: f85b0df7-d8f2-50f4-9649-5c293158b392

STIX ID: report--f85b0df7-d8f2-50f4-9649-5c293158b392

Feed Name: Detect FYI

Threat Score
35/100

Date Published: 2026-03-27

Date Updated: 2026-04-19

Author: Omar Tarek Zayed

...
...

This report provides a Kusto detection query and an explainable scoring model to identify suspicious modifications to the KslD Windows kernel driver (registry changes to the KslD service, non‑Defender AllowedProcessName entries, vulnerable ImagePath values, and driver file artifacts such as KslD.sys/vKslD.sys and a specific SHA256). The rule uses left outer joins between registry and file telemetry, flags user-writable or privileged initiators, and assigns a simple suspicion score to prioritize investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.