Esc
LSASS Memory - T1003.001
(ATT&CK® Technique)
Definition
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory. These credential materials can be harvested by an administrative user or SYSTEM and used to conduct Lateral Movement using Use Alternate Authentication Material.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.