Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs (via process_access)
This rule detects anomalous process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace. These DLLs contain functions like MiniDumpWriteDump that can be misused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll, dbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.
Unlock this rule to view and copy it
Rule logic is available with an unlock credit. The public page keeps its context, mappings and implementation details visible.
Sign in to unlockKnown false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.