LSASS Memory Dumping
Creating a memory dump of the LSASS process to extract NTLM hashes, Kerberos tickets and (on older systems) cleartext credentials for offline parsing.
The Local Security Authority Subsystem Service (lsass.exe) holds logged-on
users' credential material in memory: NTLM password hashes, Kerberos tickets,
and — if the legacy WDigest provider is still enabled — reversibly-encrypted
or cleartext passwords. Rather than attacking a hash database on disk, this
technique dumps the live process's memory and parses the credential
structures offline, entirely outside LSASS itself.
How it works
A full process memory dump of LSASS captures everything the process holds.
The dump can be produced with the same legitimate Windows facilities used for
crash diagnostics — the point is that no "hacking tool" needs to touch
LSASS directly, only a handle with PROCESS_VM_READ and a minidump-writing
API:
OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_VM_READ, FALSE, lsassPid)
MiniDumpWriteDump(hProcess, lsassPid, hDumpFile,
MiniDumpWithFullMemory, NULL, NULL, NULL)The resulting .dmp file is then parsed offline — no elevated access to the
live process is needed again, and the parsing tool never has to run on the
victim host at all if the dump is exfiltrated first.
Detection & analysis
- Static — A dropped
.dmpfile withlsassin its path or name is a strong indicator by itself; so is a binary importingMiniDumpWriteDump/OpenProcessalongside a hard-coded or dynamically resolved reference tolsass.exe. - Dynamic — Watch for
OpenProcesscalls targeting LSASS's PID withPROCESS_VM_READfrom a non-system process. Sysmon Event ID 10 (ProcessAccess) withTargetImage=lsass.exeand aGrantedAccessmask including read rights, sourced from an unexpected process, is the canonical detection. Windows Defender / EDR products commonly ship a built-in rule specifically for this access pattern. - Mitigations — LSA Protection (RunAsPPL) runs LSASS as a Protected
Process, and Credential Guard isolates secrets in a separate virtualized
container, both of which block the plain
OpenProcess/MiniDumpWriteDumppath above. Attackers who need LSASS credentials on a PPL-protected host must instead defeat process protection itself (a kernel-level bypass) — a much noisier, higher-privilege operation that is its own detection opportunity. - Tools — Sysmon (EID 10), EDR process-access telemetry, Volatility 3
(
windows.lsadump) against a full memory image,pypykatzfor offline parsing of a captured.dmpfor analysis/validation purposes.