Robuta

https://research.splunk.com/endpoint/b3b7ce35-fce5-4c73-85f4-700aeada81a9/ Detection: Windows Credential Dumping LSASS Memory Createdump | Splunk Security Content Apr 15, 2026 - Updated Date: 2026-04-15 ID: b3b7ce35-fce5-4c73-85f4-700aeada81a9 Author: Michael Haag, Splunk Type: TTP Product: Splunk Enterprise Security Description The... lsass memorydetectionwindowscredentialdumping https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/windows/credential_access_suspicious_lsass_access_memdump Potential Credential Access via LSASS Memory Dump | Prebuilt detection rules reference Identifies suspicious access to LSASS handle from a call trace pointing to DBGHelp.dll or DBGCore.dll, which both export the MiniDumpWriteDump method... credential accesslsass memorypotentialviadump https://redcanary.com/threat-detection-report/techniques/lsass-memory/ LSASS Memory - Red Canary Threat Detection Report Because of the amount of data it stores in memory, LSASS is a common target for adversaries looking to steal sensitive credentials. lsass memoryred canarythreat detectionreport