JELAJAH SOC
YO

ALT-2402 · EDR

LSASS memory access by unsigned binary

An unsigned binary in C:\Users\Public opened a handle to lsass.exe with PROCESS_VM_READ.

Back to queue
criticalClosedconfidence 83% · 1970-01-01 03:02:00Z · rule DET-0203 Credential Dumping via Process AccessLinked to INC-1041

Detection summary

An unsigned binary in C:\Users\Public opened a handle to lsass.exe with PROCESS_VM_READ.

Affected host
WS-FIN-014
Affected user
a.pratama
Source IP
10.20.14.61
Detection rule
DET-0203 Credential Dumping via Process Access
Log source
EDR
Assignee
A. Pratama

Recommended actions

  • Isolate host and capture memory image
  • Invalidate all Kerberos tickets on the host
  • Hunt for the same hash across the estate

Analyst decision

Triage checklist

  • 1. Confirm the detection logic matched genuine activity.
  • 2. Check user and asset context for expected behaviour.
  • 3. Pivot on host, user, IP and hash in the Log Explorer.
  • 4. Enrich IOCs with threat intelligence.
  • 5. Set a verdict and record your reasoning.