Credential Dumping via LSASS: Detection Gap Highlights Misuse of Legitimate Windows DLLs (ATT&CK T1003.001)
What Happened — Attackers are leveraging the signed Windows component comsvcs.dll via rundll32.exe to dump the memory of LSASS, extracting domain passwords, Kerberos tickets and NTLM hashes without triggering traditional AV/EDR signatures. The same DLL is used legitimately for crash diagnostics, making the malicious activity blend in with normal operations.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access‑Control criteria (CC6.1) require documented limits on privileged process interactions; undocumented LSASS dumps constitute a control failure.
- Continuous‑compliance programs need real‑time evidence that only authorized tools access credential stores, otherwise audit evidence is incomplete.
- Security‑awareness and policy enforcement are essential to differentiate legitimate diagnostics from malicious credential‑dumping attempts.
Who Is Affected — Enterprises that run Windows endpoints and are subject to SOC 2 audits, spanning technology, financial services, SaaS, healthcare and other regulated sectors.
Recommended Actions
- Map LSASS access to the SOC 2 logical‑access control (CC6.1) and add it to your control inventory.
- Deploy monitoring that flags any
rundll32.exeinvocation ofcomsvcs.dlltargeting LSASS, and require a ticketed justification for each occurrence. - Review and tighten privileged‑process policies; enforce least‑privilege for diagnostic tools.
- Incorporate this scenario into security‑awareness training and tabletop exercises.
Source: Broadcom Symantec Blog
Technical Notes — Technique T1003.001 (OS Credential Dumping) using a signed Windows DLL (comsvcs.dll) invoked via rundll32.exe. No new malware signature; detection relies on process‑behavior analytics and contextual ticketing. Source: same link