LSA Secrets
MITRE ATT&CK, Credential Access, Sub-technique T1003.004
Last updated
MITRE ATT&CK, Credential Access, Sub-technique T1003.004
Last updated
LSA secrets are stored in the registry at
HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets
. LSA secrets can also be dumped from memory.
When cleartext credentials are retrieved from LSA Secrets it is due to the credentials being stored for a service (E.g., creating a service with a custom user account).
To mitigate this issue, avoid using a domain account for the service. Best practice is to avoid using a domain user account for services. Rather, create a local account to run the service. If specific domain user rights are needed then create an account with the specific rights required. It should also be stated to never use a domain administrator account for a service.