Open cardosec

Case BBDDDB · Blue team / DFIR · L3 Applied

Someone Touched LSASS

Practise as: Incident drill · Interview

Live alertSysmon event 10 on file server FS-03 shows rundll32.exe opening lsass.exe with access 0x1FFFFF at 14:32; the parent was a service installed 20 minutes earlier (event 7045).

Interview questionYou see LSASS memory access from rundll32 on a server. Walk me through your response.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Likely credential dumping (T1003.001), e.g. comsvcs.dll MiniDump; assume all creds cached on FS-03 are exposed.
  2. Event 7045 new service suggests remote execution (PsExec-style); find the source host via 4624 type 3 logons.
  3. Isolate FS-03, collect memory and triage artifacts, and look for the dump file on disk.
  4. Reset every account that logged on to FS-03, prioritizing admins and service accounts; watch for their reuse.
  5. Harden: enable LSA protection (RunAsPPL), Credential Guard, and the ASR rule blocking LSASS credential theft.

If the interviewer pushes back

  • A domain admin had an active session on FS-03. What does that change, and do you reset krbtgt?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.