LoFP LoFP / t1003.001

t1003.001

TitleTags
actual failures in lsass.exe that trigger a crash dump (unlikely)
another tool that uses command line flags similar to procdump
another tool that uses the command line switches of xordump
antivirus products
av signature updates
command lines that use the same flags
false positives are expected in cases in which procdump just gets copied to a different directory without any renaming
files with mimikatz in their filename
google chrome googleupdate.exe
legitimate administrator using credential dumping tool for password recovery
legitimate administrator using tool for password recovery
legitimate application that needs to do a full dump of their process
legitimate certificate exports invoked by administrators or users (depends on processes in the environment - filter if unusable)
legitimate mssql server actions
legitimate software accessing lsass process for legitimate reason; update the whitelist with it
legitimate software such as av and edr
legitimate usage by software developers/testers
legitimate usage of adplus for debugging purposes
legitimate usage of werfaultsecure for debugging purposes
legitimate use during memory forensics; if not part of authorized analysis, warrants urgent investigation
legitimate use of procdump by a developer or administrator
naughty administrators
possibly during software installation or update processes
rare case of troubleshooting by an administrator or support that has to be investigated regardless
rare legitimate crashing of the lsass process
rare legitimate dump of the process by the operating system due to a crash of lsass
rare legitimate files with similar filename structure
rare programs that contain the word dump in their name and access lsass
some taskmgr.exe related activity
transferring sensitive files for legitimate administration work by legitimate administrator
unknown
unknown cases in which werfault accesses lsass.exe
unlikely
unlikely, because no one should dump an lsass process memory
valid user connecting using rdp
very unlikely
windows error reporting might produce similar behavior. in that case, check the pid associated with the \"-p\" parameter in the commandline.