A security analyst is reviewing endpoint telemetry for signs of lateral movement and credential dumping. Which THREE of the following event log indicators or telemetry artifacts suggest potential credential dumping activity targeting LSASS? (Choose THREE)
Sysmon Event ID 10 logs process access events, specifically highlighting interactions with critical processes like LSASS.
Why this answer
Credential dumping leaves specific traces, including abnormal handles opened to LSASS, unexpected processes reading LSASS memory, and specific Event IDs.