T1003.001LSASS Memory
T1003.001 — LSASS Memory is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 17 detection use cases covering it and 102 threat-intel articles citing it.
Credential Access
17Use cases
102Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1003 · OS Credential Dumping
Use cases covering this technique (17)
LSASS process access / dump (credential theft) Access LSASS Memory for Dump Creation Create Remote Thread into LSASS Creation of lsass Dump with Taskmgr Detect Credential Dumping through LSASS access Dump LSASS via comsvcs DLL Dump LSASS via procdump Windows Credential Dumping LSASS Memory Createdump Windows Hunting System Account Targeting Lsass Windows Non-System Account Targeting Lsass Windows Possible Credential Dumping Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity Detect Mimikatz Using Loaded Images Detect Mimikatz Via PowerShell And EventCode 4703 Dump LSASS via procdump Rename Unsigned Image Loaded by LSASS [LLM] MuddyWater CE-Notes / LP-Notes / Blub stealer staging-file writesArticles citing this technique (102)
high A tale of two eras art-40
crit CISA KEV: CVE-2026-50751 — Check Point Security Gateway Improper Authentication Vulnerability art-111
crit Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection art-178
crit ESET Threat Report H2 2025 art-647
crit CISA KEV: CVE-2025-55182 — Meta React Server Components Remote Code Execution Vulnerability art-670
high In memoriam: David Harley art-713
crit CISA KEV: CVE-2025-53770 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability art-844
crit CISA KEV: CVE-2025-5777 — Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability art-848
crit CISA KEV: CVE-2025-24472 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-956
crit CISA KEV: CVE-2024-53704 — SonicWall SonicOS SSLVPN Improper Authentication Vulnerability art-998
crit CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-1032
crit CISA KEV: CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability art-1051
crit CISA KEV: CVE-2024-50623 — Cleo Multiple Products Unrestricted File Upload Vulnerability art-1054
crit CISA KEV: CVE-2024-49039 — Microsoft Windows Task Scheduler Privilege Escalation Vulnerability art-1089
crit CISA KEV: CVE-2024-30088 — Microsoft Windows Kernel TOCTOU Race Condition Vulnerability art-1115