Open cardosec

Case 95516D · Malware & intel · L4 Advanced

Fingerprinting the LSASS dumper

Practise as: Incident drill

Live alertThree hosts show Sysmon Event 10 on lsass.exe: one from rundll32 with comsvcs.dll MiniDump, one from a renamed signed binary, and one from an unsigned process with no dump on disk.

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. GrantedAccess hints at the tool: VM_READ-style masks (0x1010/0x1410) fit in-memory readers; 0x1FFFFF is common for dump-based tools
  2. comsvcs.dll MiniDump: rundll32 command line with the LSASS PID, CallTrace via dbgcore/dbghelp, and a .dmp file write (Sysmon 11)
  3. Renamed tools: check PE OriginalFileName, signer and command-line flags; e.g. ProcDump leaves its EULA-accepted registry value
  4. No dump file plus CallTrace frames in unbacked (UNKNOWN) memory suggests injected or custom tooling reading LSASS in-process
  5. RunAsPPL and Credential Guard limit what is exposed; tools that get past PPL usually need a driver, so look for 7045/Sysmon 6

If the interviewer pushes back

  • Credential Guard is enabled on one host. Which credential material can a dump still expose there, and which can it not?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.