Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0437 — Detection of LSA Secrets Dumping via Registry and Memory Extraction
DET0437

Detection of LSA Secrets Dumping via Registry and Memory Extraction

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1212 Analytic 1212
Windows

Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz.

WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=7
[TargetObject] Target registry paths like HKLM\SECURITY\Policy\Secrets or variants can be tuned depending on OS version or registry redirection settings.
[ImageLoaded] Module names such as `lsasrv.dll`, `sechost.dll`, or suspicious DLLs loaded by user processes may require tuning for known-good service operations.
[AccessMask] Tuning based on whether processes are using specific sensitive access rights (e.g., 0x2 or 0x4).
[TimeWindow] Temporal window between registry access and command-line tool execution.

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0437
STIX ID
x-mitre-detection-strategy--c29886a9-676a-441a-adcd-6f239f8eb6b0
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.