kevmap

TechniquesT1003 › AN0648

AN0648 Analytic 0648

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Processes accessing LSASS memory or SAM registry hives outside of trusted security tools, often followed by file creation or lateral movement. Detects unauthorized access to sensitive OS subsystems for credential extraction.</p>
Detects
T1003 OS Credential Dumping
Part of
DET0234 Credential Dumping via Sensitive Memory and Registry Access Correlation

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=10DC0035 Process Access
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SecurityEventCode=4663, 4670, 4656DC0055 File Access
WinEventLog:SecurityEventCode=4662DC0071 Active Directory Object Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AccessMaskSet to detect full access rights (0x1F0FFF) or modify based on tool behavior.
TimeWindowDefine how soon access to LSASS is followed by suspicious file or registry activity.
ParentProcessFilterAllowlist known security tools or system processes accessing LSASS.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2019-0604Microsoft SharePointMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-13608Citrix StoreFront ServerMapped
CVE-2020-5902F5 BIG-IPStale
CVE-2021-22893Ivanti Pulse Connect SecureMapped
CVE-2021-40539Zoho ManageEngineMapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusMapped
CVE-2021-44515Zoho Desktop CentralMapped
CVE-2023-28252Microsoft WindowsMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-48248NAKIVO Backup and ReplicationMapped
CVE-2024-57727SimpleHelp SimpleHelpMapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-21333Microsoft WindowsMapped
CVE-2025-21334Microsoft WindowsMapped
CVE-2025-21335Microsoft WindowsMapped
CVE-2025-32709Microsoft WindowsMapped
CVE-2025-32756Fortinet Multiple ProductsMapped