LetMeowIn - Analysis of a Credential Dumper
ID: 4a7766a0-d292-530e-809f-b93571723002
STIX ID: report--4a7766a0-d292-530e-809f-b93571723002
Feed Name: Binary Defense Blog
ARC Labs analyzes LetMeowIn, a Windows LSASS credential-dumping tool that leverages MiniDumpWriteDump with in-memory manipulation and multiple evasion techniques (API obfuscation, indirect syscalls, ETW tampering, hijacking existing LSASS handles via NtDuplicateObject, and corrupting dump signatures) to bypass endpoint security; the report confirms the tool can dump LSASS while EDRs are present and provides practical detection recommendations including process creation and Sysmon monitoring, handle-manipulation auditing, registry SACLs for MiniDumpAuxiliaryDlls, and heuristics for dump file creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
