Cross-source coverage

T1003.004 / ATT&CK

OS Credential Dumping: LSA Secrets

21 rules across 4 sources.

From MITRE ATT&CK 19.2

Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets. LSA secrets can also be dumped from memory.

Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.

Platforms
Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmon

How MITRE says to detect it DET0437

Detection of LSA Secrets Dumping via Registry and Memory Extraction

Windows Analytic 1212

Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz.

  • WinEventLog:Security EventCode=4663, 4670, 4656
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=10
  • WinEventLog:Sysmon EventCode=7

SigmaHQ/sigma

12 rules
Detection Severity Format
HackTool - Credential Dumping Tools Named Pipe Created Critical Sigma
Cred Dump Tools Dropped Files High Sigma
Credential Dumping Tools Service Execution - Security High Sigma
Credential Dumping Tools Service Execution - System High Sigma
DPAPI Domain Backup Key Extraction High Sigma
Dumping of Sensitive Hives Via Reg.EXE High Sigma
HackTool - Mimikatz Execution High Sigma
Mimikatz Use High Sigma
Possible Impacket SecretDump Remote Activity High Sigma
Possible Impacket SecretDump Remote Activity - Zeek High Sigma

+ 2 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

5 rules
Detection Severity Format
Potential Invoke-Mimikatz PowerShell Script Critical Elastic TOML
Credential Acquisition via Registry Hive Dumping High Elastic TOML
PowerShell Invoke-NinjaCopy script High Elastic TOML
Sensitive Registry Hive Access via RegBack High Elastic TOML
Suspicious Remote Registry Access via SeBackupPrivilege Medium Elastic TOML

elastic/protections-artifacts

3 rules
Detection Severity Format
Remote Access to Sensitive Registry Keys Undefined Elastic TOML
Suspicious Access to LSA Secrets Registry Undefined Elastic TOML
System BootKey Registry Access Undefined Elastic TOML

splunk/security_content

1 rule
Detection Severity Format
Windows LSA Secrets NoLMhash Registry Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.