Possible LSASS Process Dump Through Procdump (via process_creation)
This rule detects potential credential harvesting attempts through LSASS memory dumps using ProcDump. This rule flags anomalous command-line patterns that combine memory dump flags (-ma, -mm, -mp) with LSASS-related process markers. LSASS (Local Security Authority Subsystem Service) contains sensitive authentication data including plaintext passwords, NTLM hashes, and Kerberos tickets in memory. Attackers frequently dump LSASS memory to extract credentials for lateral movement and privilege escalation.
Unlock this rule to view and copy it
Rule logic is available with an unlock credit. The public page keeps its context, mappings and implementation details visible.
Sign in to unlockKnown false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.