Cross-source coverage
T1003.004 / ATT&CK
OS Credential Dumping: LSA Secrets
21 rules across 4 sources.
From MITRE ATT&CK 19.2
Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets. LSA secrets can also be dumped from memory.
Reg can be used to extract from the Registry. Mimikatz can be used to extract secrets from memory.
- Tactics
- Credential Access
- Platforms
- Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmon
How MITRE says to detect it DET0437
Detection of LSA Secrets Dumping via Registry and Memory Extraction
Windows Analytic 1212
Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz.
WinEventLog:SecurityEventCode=4663, 4670, 4656WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=10WinEventLog:SysmonEventCode=7
SigmaHQ/sigma
12 rules| Detection | Severity | Format |
|---|---|---|
| HackTool - Credential Dumping Tools Named Pipe Created | Critical | Sigma |
| Cred Dump Tools Dropped Files | High | Sigma |
| Credential Dumping Tools Service Execution - Security | High | Sigma |
| Credential Dumping Tools Service Execution - System | High | Sigma |
| DPAPI Domain Backup Key Extraction | High | Sigma |
| Dumping of Sensitive Hives Via Reg.EXE | High | Sigma |
| HackTool - Mimikatz Execution | High | Sigma |
| Mimikatz Use | High | Sigma |
| Possible Impacket SecretDump Remote Activity | High | Sigma |
| Possible Impacket SecretDump Remote Activity - Zeek | High | Sigma |
+ 2 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
5 rules| Detection | Severity | Format |
|---|---|---|
| Potential Invoke-Mimikatz PowerShell Script | Critical | Elastic TOML |
| Credential Acquisition via Registry Hive Dumping | High | Elastic TOML |
| PowerShell Invoke-NinjaCopy script | High | Elastic TOML |
| Sensitive Registry Hive Access via RegBack | High | Elastic TOML |
| Suspicious Remote Registry Access via SeBackupPrivilege | Medium | Elastic TOML |
elastic/protections-artifacts
3 rules| Detection | Severity | Format |
|---|---|---|
| Remote Access to Sensitive Registry Keys | Undefined | Elastic TOML |
| Suspicious Access to LSA Secrets Registry | Undefined | Elastic TOML |
| System BootKey Registry Access | Undefined | Elastic TOML |
splunk/security_content
1 rule| Detection | Severity | Format |
|---|---|---|
| Windows LSA Secrets NoLMhash Registry | Undefined | SPL |