Various LSASS Credentials Dumping Methods Detected by EDR
ID: 1c44428a-5802-5748-a3ed-0c08f74e8f9e
STIX ID: report--1c44428a-5802-5748-a3ed-0c08f74e8f9e
Feed Name: ASEC
AhnLab ASEC describes credential-theft techniques in Windows Active Directory environments centered on dumping LSASS memory to obtain NT hashes for pass-the-hash and lateral movement, highlighting the use of both Mimikatz and legitimate tools (ProcDump, Process Explorer, Task Manager, comsvcs.dll) to evade traditional detections. The report emphasizes behavior-based detection and response by AhnLab EDR to surface, analyze, and mitigate these credential access attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
