An attacker has compromised a Windows workstation and successfully injected a beacon into a legitimate process. They wish to perform lateral movement using Mimikatz to extract credentials from LSASS. Which technique minimizes the likelihood of triggering endpoint detection for credential dumping?
Trap 1: Invoke Mimikatz 'sekurlsa::logonpasswords' directly from the…
Executing this command directly triggers immediate alerts in modern EDR systems due to the known signature of the Mimikatz binary and the specific API calls used to read LSASS memory. Security teams monitor for these process patterns, making this approach highly likely to result in immediate detection.
Trap 2: Use the 'lsadump::sam' command while running as a standard user.
This command requires local administrator privileges to access the SAM registry hive. Running this as a standard user will fail due to insufficient permissions. Even if attempted, it provides no path to plaintext credentials, and the failed access attempts are easily logged by security monitoring systems.
Trap 3: Inject a malicious DLL into the LSASS process space to capture…
Injecting code into LSASS is an extremely invasive technique that is heavily monitored by endpoint security tools. Process injection into critical system services triggers behavioral alerts because it violates standard integrity boundaries. This method is considered loud and is likely to cause an immediate system crash.
- A
Invoke Mimikatz 'sekurlsa::logonpasswords' directly from the command line.
Why it fails: Executing this command directly triggers immediate alerts in modern EDR systems due to the known signature of the Mimikatz binary and the specific API calls used to read LSASS memory. Security teams monitor for these process patterns, making this approach highly likely to result in immediate detection.
- B
Use the 'lsadump::sam' command while running as a standard user.
Why it fails: This command requires local administrator privileges to access the SAM registry hive. Running this as a standard user will fail due to insufficient permissions. Even if attempted, it provides no path to plaintext credentials, and the failed access attempts are easily logged by security monitoring systems.
- C
Create a minidump of the LSASS process and exfiltrate it for offline analysis.
Creating a minidump of the LSASS process is a common technique that can be performed using legitimate tools like ProcDump or PowerShell. By moving the dump file to an offline machine for processing, the attacker avoids running suspicious memory-scraping code on the target host, successfully bypassing live detection.
- D
Inject a malicious DLL into the LSASS process space to capture passwords.
Why it fails: Injecting code into LSASS is an extremely invasive technique that is heavily monitored by endpoint security tools. Process injection into critical system services triggers behavioral alerts because it violates standard integrity boundaries. This method is considered loud and is likely to cause an immediate system crash.