Windows Security: Suspicious AccessMask/AccessList Requested on LSASS (lsass.exe) Handle
Flags processes requesting potentially credential-dumping-related access to LSASS based on Security Event 4656/4663.
- Product
- windows
- Service
- security
- Author
- Roberto Rodriguez, Teymur Kheirkhabarov, Dimitrios Slamaris, Mark Russinovich, Aleksey Potapov, oscd.community (update) (SigmaHQ), DRL 1.1
- Published
- 2019-11-01
- Updated
- 2026-07-31
ATT&CK techniques
Cred AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows Security events where a process requests a handle to the LSASS process (lsass.exe) with access masks or access lists commonly associated with sensitive credential access attempts. Such requests matter because they can indicate attempts to read memory or otherwise interact with LSASS, which can lead to credential dumping. It relies on handle request and access attempt telemetry from Security logs (EventID 4656 and 4663) including object name and access details, with additional process-name filtering to reduce expected legitimate activity.
Reporting behind it
- web.archive.orghttps://web.archive.org/web/20230208123920/https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html
- slideshare.nethttps://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_susp_lsass_dump_generic.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows Security: Suspicious AccessMask/AccessList Requested on LSASS (lsass.exe) Handle"
id: 5a0d0944-cc89-45a2-a419-92a587c96a5d
status: test
description: This rule flags Windows Security events where a process requests a handle to the LSASS process (lsass.exe) with access masks or access lists commonly associated with sensitive credential access attempts. Such requests matter because they can indicate attempts to read memory or otherwise interact with LSASS, which can lead to credential dumping. It relies on handle request and access attempt telemetry from Security logs (EventID 4656 and 4663) including object name and access details, with additional process-name filtering to reduce expected legitimate activity.
references:
- https://web.archive.org/web/20230208123920/https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for_22.html
- https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_susp_lsass_dump_generic.yml
author: Roberto Rodriguez, Teymur Kheirkhabarov, Dimitrios Slamaris, Mark Russinovich, Aleksey Potapov, oscd.community (update), Huntrule Team
date: 2019-11-01
modified: 2026-06-29
tags:
- attack.credential-access
- car.2019-04-004
- attack.t1003.001
logsource:
product: windows
service: security
detection:
selection_1:
EventID: 4656
ObjectName|endswith: \lsass.exe
AccessMask|contains:
- "0x40"
- "0x1400"
- "0x100000"
- "0x1410"
- "0x1010"
- "0x1438"
- "0x143a"
- "0x1418"
- "0x1f0fff"
- "0x1f1fff"
- "0x1f2fff"
- "0x1f3fff"
selection_2:
EventID: 4663
ObjectName|endswith: \lsass.exe
AccessList|contains:
- "4484"
- "4416"
filter_main_specific:
ProcessName|endswith:
- \csrss.exe
- \GamingServices.exe
- \lsm.exe
- \MicrosoftEdgeUpdate.exe
- \minionhost.exe
- \MRT.exe
- \MsMpEng.exe
- \perfmon.exe
- \procexp.exe
- \procexp64.exe
- \procexp64a.exe
- \svchost.exe
- \taskmgr.exe
- \thor.exe
- \thor64.exe
- \vmtoolsd.exe
- \VsTskMgr.exe
- \wininit.exe
- \wmiprvse.exe
- RtkAudUService64
ProcessName|contains:
- :\Program Files (x86)\
- :\Program Files\
- :\ProgramData\Microsoft\Windows Defender\Platform\
- :\Windows\SysNative\
- :\Windows\System32\
- :\Windows\SysWow64\
- :\Windows\Temp\asgard2-agent\
filter_main_generic:
ProcessName|contains: :\Program Files
filter_main_exact:
ProcessName|endswith:
- :\Windows\System32\taskhostw.exe
- :\Windows\System32\msiexec.exe
- :\Windows\CCM\CcmExec.exe
filter_main_sysmon:
ProcessName|endswith:
- :\Windows\Sysmon64.exe
- :\Windows\Sysmon64a.exe
AccessList|contains: "%%4484"
filter_main_aurora:
ProcessName|contains: :\Windows\Temp\asgard2-agent-sc\aurora\
ProcessName|endswith: \aurora-agent-64.exe
AccessList|contains: "%%4484"
filter_main_scenarioengine:
ProcessName|endswith: \x64\SCENARIOENGINE.EXE
AccessList|contains: "%%4484"
filter_main_avira1:
ProcessName|contains|all:
- :\Users\
- \AppData\Local\Temp\is-
ProcessName|endswith: \avira_system_speedup.tmp
AccessList|contains: "%%4484"
filter_main_avira2:
ProcessName|contains: :\Windows\Temp\
ProcessName|endswith: \avira_speedup_setup_update.tmp
AccessList|contains: "%%4484"
filter_main_snmp:
ProcessName|endswith: :\Windows\System32\snmp.exe
AccessList|contains: "%%4484"
filter_main_googleupdate:
ProcessName|contains: :\Windows\SystemTemp\
ProcessName|endswith: \GoogleUpdate.exe
AccessList|contains: "%%4484"
filter_optional_procmon:
ProcessName|endswith:
- \procmon64.exe
- \procmon64a.exe
- \procmon.exe
AccessList|contains: "%%4484"
condition: 1 of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Legitimate software accessing LSASS process for legitimate reason; update the whitelist with it
level: medium
license: DRL-1.1
related:
- id: 4a1b6da0-d94f-4fc3-98fc-2d9cb9e5ee76
type: derived