https://research.splunk.com/endpoint/b3b7ce35-fce5-4c73-85f4-700aeada81a9/
Detection: Windows Credential Dumping LSASS Memory Createdump | Splunk Security Content
Apr 15, 2026 - Updated Date: 2026-04-15 ID: b3b7ce35-fce5-4c73-85f4-700aeada81a9 Author: Michael Haag, Splunk Type: TTP Product: Splunk Enterprise Security Description The...
lsass memorydetectionwindowscredentialdumping
https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/windows/credential_access_suspicious_lsass_access_memdump
Potential Credential Access via LSASS Memory Dump | Prebuilt detection rules reference
Identifies suspicious access to LSASS handle from a call trace pointing to DBGHelp.dll or DBGCore.dll, which both export the MiniDumpWriteDump method...
credential accesslsass memorypotentialviadump
https://redcanary.com/threat-detection-report/techniques/lsass-memory/
LSASS Memory - Red Canary Threat Detection Report
Because of the amount of data it stores in memory, LSASS is a common target for adversaries looking to steal sensitive credentials.
lsass memoryred canarythreat detectionreport