logo

The Detection Gap: MITRE ATT&CK T1003.001

ID: c47c2a5a-2ad5-5617-91cc-f6c24e823c16

STIX ID: report--c47c2a5a-2ad5-5617-91cc-f6c24e823c16

Feed Name: security.com

Threat Score
75/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Kirk Hasty

...
...

This Detection Gap article explains how attackers abuse legitimate, signed Windows components (comsvcs.dll invoked via rundll32.exe or Windows Error Reporting via IFEO) to dump LSASS memory and steal credentials. It contrasts legitimate diagnostic dumps with malicious usage by highlighting suspicious command lines, parent process lineage, dump file locations, and lack of supporting tickets, and offers detection and hunting guidance (cross-process access, NtReadVirtualMemory, parent tracing, filemod correlation) plus posture recommendations like Credential Guard deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.