logo

Various LSASS Credentials Dumping Methods Detected by EDR

ID: 1c44428a-5802-5748-a3ed-0c08f74e8f9e

STIX ID: report--1c44428a-5802-5748-a3ed-0c08f74e8f9e

Feed Name: ASEC

Date Published: 2024-01-22

Date Updated: 2026-04-26

Author: Sanseo

...
...

AhnLab ASEC describes credential-theft techniques in Windows Active Directory environments centered on dumping LSASS memory to obtain NT hashes for pass-the-hash and lateral movement, highlighting the use of both Mimikatz and legitimate tools (ProcDump, Process Explorer, Task Manager, comsvcs.dll) to evade traditional detections. The report emphasizes behavior-based detection and response by AhnLab EDR to surface, analyze, and mitigate these credential access attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.