T1003.001 CrowdStrike LogScale · LogScale

Detect LSASS Memory in CrowdStrike LogScale

Adversaries access credential material stored in the LSASS process memory. After logon, Windows stores credentials (NTLM hashes, Kerberos tickets, plaintext passwords via WDigest) in LSASS. Tools used include Mimikatz, ProcDump, comsvcs.dll MiniDump (rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump), WerFault silent process exit, and Cobalt Strike's sekurlsa module. Used extensively by APT1, APT33, OilRig, HAFNIUM, Volt Typhoon, NotPetya, Cobalt Strike operators, and many others. Highest-frequency credential dumping technique observed in the wild.

MITRE ATT&CK

Tactic
Credential Access
Technique
T1003 OS Credential Dumping
Sub-technique
T1003.001 LSASS Memory
Canonical reference
https://attack.mitre.org/techniques/T1003/001/

LogScale Detection Query

CrowdStrike LogScale (LogScale)
cql
/* T1003.001 — LSASS Memory Credential Dumping */

/* Pattern 1: Suspicious process accessing LSASS memory (Sysmon-like via CrowdStrike LsassCall events) */
#event_simpleName = "LsassCall"
| TargetProcessImageFileName = /(?i)lsass\.exe/
| SourceProcessImageFileName != /(?i)(MsMpEng|csrss|services|lsm|svchost|winlogon|wininit|SecurityHealthService|SenseIR)\.exe/
| DesiredAccess in ["0x1fffff", "0x1f3fff", "0x143a", "0x1410", "0x1010", "0x40"]
| table([_timeutc, ComputerName, SourceProcessImageFileName, SourceProcessCommandLine, DesiredAccess, UserName])

union

/* Pattern 2: rundll32 executing comsvcs.dll MiniDump */
#event_simpleName = "ProcessRollup2"
| ImageFileName = /(?i)rundll32\.exe/
| CommandLine = /(?i)comsvcs/
| CommandLine = /(?i)MiniDump/
| table([_timeutc, ComputerName, ImageFileName, CommandLine, UserName, SHA256HashData])

union

/* Pattern 3: ProcDump targeting lsass */
#event_simpleName = "ProcessRollup2"
| ImageFileName = /(?i)procdump(64)?\.exe/
| CommandLine = /(?i)lsass/
| table([_timeutc, ComputerName, ImageFileName, CommandLine, UserName, SHA256HashData])

union

/* Pattern 4: Known credential dumping tool names */
#event_simpleName = "ProcessRollup2"
| ImageFileName = /(?i)(mimikatz|mimilib|wce|gsecdump|sqldumper)\.exe/
| table([_timeutc, ComputerName, ImageFileName, CommandLine, UserName, SHA256HashData, MD5HashData])

| sort(field=_timeutc, order=desc)
critical severity high confidence

CrowdStrike LogScale (Falcon) query detecting LSASS credential dumping via four patterns: LsassCall events with elevated access masks targeting lsass.exe, rundll32 executing comsvcs.dll MiniDump, ProcDump targeting lsass by command line, and execution of known credential dumping tool names. Unions all patterns for unified alerting.

Data Sources

CrowdStrike Falcon Endpoint (ProcessRollup2, LsassCall)Falcon Data Replicator

Required Tables

LsassCallProcessRollup2

False Positives & Tuning

  • CrowdStrike Falcon sensor itself (CSFalconService, CSAgent) may appear in LsassCall events on endpoints during threat intelligence operations — validate sensor version and exclude known Falcon process names
  • sqldumper.exe on SQL Server hosts accessing LSASS during legitimate SQL memory dump generation — correlate with SQL Server service activity and restrict alert to non-database server asset groups
  • Authorized penetration testing tools executed by the internal red team — confirm against change management tickets and limit scope using ComputerName allowlists or asset tags in the query
Download portable Sigma rule (.yml)

Other platforms for T1003.001


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1LSASS Dump via comsvcs.dll MiniDump (LOLBin)

    Expected signal: Sysmon Event ID 1: Process Create for rundll32.exe with CommandLine containing comsvcs.dll MiniDump. Sysmon Event ID 10: ProcessAccess for lsass.exe from rundll32.exe with GrantedAccess=0x1fffff. Sysmon Event ID 11: FileCreate for the .dmp file in C:\Windows\Temp\.

  2. Test 2LSASS Access via PowerShell Reflection (Mimikatz-Style)

    Expected signal: Sysmon Event ID 10: ProcessAccess with TargetImage=lsass.exe, SourceImage=powershell.exe. The GrantedAccess value depends on the access requested by Get-Process. Security Event ID 4656/4663 if process object auditing is enabled.

  3. Test 3LSASS Dump via ProcDump

    Expected signal: Sysmon Event ID 10: ProcessAccess with TargetImage=lsass.exe, SourceImage=procdump.exe, GrantedAccess=0x1fffff. Sysmon Event ID 11: FileCreate for lsass_pd_test.dmp. Sysmon Event ID 1: Process Create for procdump.exe with lsass.exe in CommandLine.

Unlock Pro Content

Get the full detection package for T1003.001 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections