Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.
.claude/skills/detecting-t1003-credential-dumping-with-edr/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | — | — |
| case-16 | ✗→✓ | ▲ Improved | — | — |
| case-03 | ✗→✓ | ▲ Improved | — | — |
| case-17 | ✗→✓ | ▲ Improved | — | — |
| case-23 | ✗→✗ | = Same ✗ | — | — |
| Concept | Description | |---------|-------------| | T1003.001 | LSASS Memory -- dumping credentials from LSASS process | | T1003.002 | Security Account Manager -- extracting local account hashes from SAM | | T1003.003 | NTDS -- extracting domain hashes from Active Directory database | | T1003.004 | LSA Secrets -- extracting service account passwords | | T1003.005 | Cached Domain Credentials -- extracting DCC2 hashes | | T1003.006 | DCSync -- replicating credentials from domain controller | | Credential Guard | Virtualization-based isolation of LSASS secrets | | RunAsPPL | Protected Process Light for LSASS |
splindex=sysmon EventCode=10 | where match(TargetImage, "(?i)lsass\.exe$") | where GrantedAccess IN ("0x1FFFFF", "0x1F3FFF", "0x143A", "0x1F0FFF", "0x0040", "0x1010", "0x1410") | where NOT match(SourceImage, "(?i)(csrss|lsass|svchost|MsMpEng|WmiPrvSE|taskmgr|procexp|SecurityHealthService)\.exe$") | table _time Computer SourceImage SourceProcessId GrantedAccess CallTrace
splindex=sysmon EventCode=1 | where match(CommandLine, "(?i)(sekurlsa|lsadump|kerberos::list|crypto::certificates)") OR match(CommandLine, "(?i)procdump.*-ma.*lsass") OR match(CommandLine, "(?i)comsvcs\.dll.*MiniDump") OR match(CommandLine, "(?i)ntdsutil.*\"ac i ntds\".*ifm") OR match(CommandLine, "(?i)reg\s+save\s+hklm\\\\(sam|security|system)") OR match(CommandLine, "(?i)vssadmin.*create\s+shadow") | table _time Computer User Image CommandLine ParentImage
kqlDeviceEvents | where Timestamp > ago(7d) | where ActionType in ("LsassAccess", "CredentialDumpingActivity") | project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, ActionType, AdditionalFields | sort by Timestamp desc
yamltitle: LSASS Memory Credential Dumping Attempt status: stable logsource: product: windows category: process_access detection: selection: TargetImage|endswith: '\lsass.exe' GrantedAccess|contains: - '0x1FFFFF' - '0x1F3FFF' - '0x143A' - '0x0040' filter: SourceImage|endswith: - '\csrss.exe' - '\lsass.exe' - '\MsMpEng.exe' - '\svchost.exe' condition: selection and not filter level: critical tags: - attack.credential_access - attack.t1003.001
sekurlsa::logonpasswords to extract plaintext passwords, NTLM hashes, and Kerberos tickets.procdump.exe -ma lsass.exe lsass.dmp creating a memory dump for offline credential extraction.rundll32.exe comsvcs.dll MiniDump [LSASS_PID] dump.bin full using a built-in Windows DLL for LSASS dumping.reg save HKLM\SAM sam.save followed by reg save HKLM\SYSTEM system.save for local account hash extraction.Hunt ID: TH-CRED-[DATE]-[SEQ]
Host: [Hostname]
Dumping Method: [LSASS_Access/NTDS/SAM/DCSync]
Source Process: [Tool or process used]
Target: [LSASS/NTDS.dit/SAM/SECURITY]
Access Rights: [Granted access mask]
User Context: [Account performing the dump]
ATT&CK Technique: [T1003.00x]
Risk Level: [Critical/High/Medium]
Credentials at Risk: [Scope assessment]| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-23 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-24 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-07 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-22 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-01 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-09 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-16 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-03 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-21 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 24 cases were attempted. The headline lift of +17 percentage points is the difference between those two pass rates over the 24 comparable cases.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.