Techniques › T1003 › AN0648
AN0648 Analytic 0648
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Processes accessing LSASS memory or SAM registry hives outside of trusted security tools, often followed by file creation or lateral movement. Detects unauthorized access to sensitive OS subsystems for credential extraction.</p>
- Detects
- T1003 OS Credential Dumping
- Part of
- DET0234 Credential Dumping via Sensitive Memory and Registry Access Correlation
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Sysmon | EventCode=10 | DC0035 Process Access |
| WinEventLog:Sysmon | EventCode=1 | DC0032 Process Creation |
| WinEventLog:Security | EventCode=4663, 4670, 4656 | DC0055 File Access |
| WinEventLog:Security | EventCode=4662 | DC0071 Active Directory Object Access |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AccessMask | Set to detect full access rights (0x1F0FFF) or modify based on tool behavior. |
TimeWindow | Define how soon access to LSASS is followed by suspicious file or registry activity. |
ParentProcessFilter | Allowlist known security tools or system processes accessing LSASS. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2019-0604 | Microsoft SharePoint | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | Mapped |
| CVE-2019-13608 | Citrix StoreFront Server | Mapped |
| CVE-2020-5902 | F5 BIG-IP | Stale |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | Mapped |
| CVE-2023-28252 | Microsoft Windows | Mapped |
| CVE-2024-4577 | PHP Group PHP | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Mapped |
| CVE-2025-21333 | Microsoft Windows | Mapped |
| CVE-2025-21334 | Microsoft Windows | Mapped |
| CVE-2025-21335 | Microsoft Windows | Mapped |
| CVE-2025-32709 | Microsoft Windows | Mapped |
| CVE-2025-32756 | Fortinet Multiple Products | Mapped |