Skip to content
Credential Accessintermediate

LSASS Memory Dumping

Creating a memory dump of the LSASS process to extract NTLM hashes, Kerberos tickets and (on older systems) cleartext credentials for offline parsing.

The Local Security Authority Subsystem Service (lsass.exe) holds logged-on users' credential material in memory: NTLM password hashes, Kerberos tickets, and — if the legacy WDigest provider is still enabled — reversibly-encrypted or cleartext passwords. Rather than attacking a hash database on disk, this technique dumps the live process's memory and parses the credential structures offline, entirely outside LSASS itself.

How it works

A full process memory dump of LSASS captures everything the process holds. The dump can be produced with the same legitimate Windows facilities used for crash diagnostics — the point is that no "hacking tool" needs to touch LSASS directly, only a handle with PROCESS_VM_READ and a minidump-writing API:

text
OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_VM_READ, FALSE, lsassPid)
MiniDumpWriteDump(hProcess, lsassPid, hDumpFile,
                  MiniDumpWithFullMemory, NULL, NULL, NULL)

The resulting .dmp file is then parsed offline — no elevated access to the live process is needed again, and the parsing tool never has to run on the victim host at all if the dump is exfiltrated first.

Detection & analysis

  • Static — A dropped .dmp file with lsass in its path or name is a strong indicator by itself; so is a binary importing MiniDumpWriteDump/OpenProcess alongside a hard-coded or dynamically resolved reference to lsass.exe.
  • Dynamic — Watch for OpenProcess calls targeting LSASS's PID with PROCESS_VM_READ from a non-system process. Sysmon Event ID 10 (ProcessAccess) with TargetImage = lsass.exe and a GrantedAccess mask including read rights, sourced from an unexpected process, is the canonical detection. Windows Defender / EDR products commonly ship a built-in rule specifically for this access pattern.
  • Mitigations — LSA Protection (RunAsPPL) runs LSASS as a Protected Process, and Credential Guard isolates secrets in a separate virtualized container, both of which block the plain OpenProcess/MiniDumpWriteDump path above. Attackers who need LSASS credentials on a PPL-protected host must instead defeat process protection itself (a kernel-level bypass) — a much noisier, higher-privilege operation that is its own detection opportunity.
  • Tools — Sysmon (EID 10), EDR process-access telemetry, Volatility 3 (windows.lsadump) against a full memory image, pypykatz for offline parsing of a captured .dmp for analysis/validation purposes.
Votes

Comments(0)