The Detection Gap: MITRE ATT&CK T1003.001
ID: c47c2a5a-2ad5-5617-91cc-f6c24e823c16
STIX ID: report--c47c2a5a-2ad5-5617-91cc-f6c24e823c16
Feed Name: security.com
This Detection Gap article explains how attackers abuse legitimate, signed Windows components (comsvcs.dll invoked via rundll32.exe or Windows Error Reporting via IFEO) to dump LSASS memory and steal credentials. It contrasts legitimate diagnostic dumps with malicious usage by highlighting suspicious command lines, parent process lineage, dump file locations, and lack of supporting tickets, and offers detection and hunting guidance (cross-process access, NtReadVirtualMemory, parent tracing, filemod correlation) plus posture recommendations like Credential Guard deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
