ALT-2402 · EDR
LSASS memory access by unsigned binary
An unsigned binary in C:\Users\Public opened a handle to lsass.exe with PROCESS_VM_READ.
criticalClosedconfidence 83% · 1970-01-01 03:02:00Z · rule DET-0203 Credential Dumping via Process AccessLinked to INC-1041
Detection summary
An unsigned binary in C:\Users\Public opened a handle to lsass.exe with PROCESS_VM_READ.
- Affected host
- WS-FIN-014
- Affected user
- a.pratama
- Source IP
- 10.20.14.61
- Detection rule
- DET-0203 Credential Dumping via Process Access
- Log source
- EDR
- Assignee
- A. Pratama
Recommended actions
- Isolate host and capture memory image
- Invalidate all Kerberos tickets on the host
- Hunt for the same hash across the estate
Analyst decision
Triage checklist
- 1. Confirm the detection logic matched genuine activity.
- 2. Check user and asset context for expected behaviour.
- 3. Pivot on host, user, IP and hash in the Log Explorer.
- 4. Enrich IOCs with threat intelligence.
- 5. Set a verdict and record your reasoning.