LSASS Memory
MITRE ATT&CK, Credential Access, Sub-technique T1003.001
Last updated
MITRE ATT&CK, Credential Access, Sub-technique T1003.001
Last updated
Adversaries commonly abuse the Local Security Authority Subsystem Service (LSASS) to dump credentials for privilege escalation, data theft, and lateral movement. The process is a fruitful target for adversaries because of the sheer amount of sensitive information it stores in memory.