Case 95516D · Malware & intel · L4 Advanced
Fingerprinting the LSASS dumper
Practise as: Incident drill
Live alertThree hosts show Sysmon Event 10 on lsass.exe: one from rundll32 with comsvcs.dll MiniDump, one from a renamed signed binary, and one from an unsigned process with no dump on disk.
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- GrantedAccess hints at the tool: VM_READ-style masks (0x1010/0x1410) fit in-memory readers; 0x1FFFFF is common for dump-based tools
- comsvcs.dll MiniDump: rundll32 command line with the LSASS PID, CallTrace via dbgcore/dbghelp, and a .dmp file write (Sysmon 11)
- Renamed tools: check PE OriginalFileName, signer and command-line flags; e.g. ProcDump leaves its EULA-accepted registry value
- No dump file plus CallTrace frames in unbacked (UNKNOWN) memory suggests injected or custom tooling reading LSASS in-process
- RunAsPPL and Credential Guard limit what is exposed; tools that get past PPL usually need a driver, so look for 7045/Sysmon 6
If the interviewer pushes back
- Credential Guard is enabled on one host. Which credential material can a dump still expose there, and which can it not?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.