Which TWO of the following indicators are highly suggestive of credential dumping activity in memory?
Trap 1: lsass.exe process opening a handle to a browser process.
LSASS typically does not initiate handles to browsers. If this were observed, it would likely indicate a system anomaly or corruption rather than credential dumping, which involves other processes reading LSASS memory, not the reverse. This does not represent the standard pattern for known credential theft techniques.
Trap 2: A non-system process requesting PROCESS_QUERY_LIMITED_INFORMATION…
While many processes query information about LSASS, this specific access right is often legitimate for system monitoring or anti-virus agents. A more definitive indicator would be requests for full memory access rights, such as PROCESS_VM_READ, which are required for dumping sensitive memory contents like password hashes.
Trap 3: Increase in network traffic volume on port 53.
Network traffic on port 53 relates to DNS resolution activity. While DNS tunneling can occur, it is unrelated to credential dumping. Credential dumping is a local host activity focused on memory manipulation and does not inherently rely on or manifest through changes in DNS traffic patterns.
- A
lsass.exe process opening a handle to a browser process.
Why it fails: LSASS typically does not initiate handles to browsers. If this were observed, it would likely indicate a system anomaly or corruption rather than credential dumping, which involves other processes reading LSASS memory, not the reverse. This does not represent the standard pattern for known credential theft techniques.
- B
A non-system process requesting PROCESS_QUERY_LIMITED_INFORMATION on lsass.exe.
Why it fails: While many processes query information about LSASS, this specific access right is often legitimate for system monitoring or anti-virus agents. A more definitive indicator would be requests for full memory access rights, such as PROCESS_VM_READ, which are required for dumping sensitive memory contents like password hashes.
- C
A user-mode process requesting PROCESS_VM_READ access to lsass.exe.
The PROCESS_VM_READ access right is necessary for an external process to read the memory space of LSASS, which is where credentials are stored. Detecting this specific access request from an unauthorized process is a highly reliable indicator of credential dumping attempts by attackers using tools like Mimikatz.
- D
An unsigned binary executing from C:\Windows\Temp.
Attackers frequently drop credential dumping binaries in temp directories to avoid detection. Executing unsigned code from these locations is a common behavior of post-exploitation frameworks. Combined with memory access patterns, this serves as a critical indicator of malicious intent, especially when the binary matches known tool signatures.
- E
Increase in network traffic volume on port 53.
Why it fails: Network traffic on port 53 relates to DNS resolution activity. While DNS tunneling can occur, it is unrelated to credential dumping. Credential dumping is a local host activity focused on memory manipulation and does not inherently rely on or manifest through changes in DNS traffic patterns.