cyber-detecting-t1003-credential-dumping-with-edr - Detecting T1003 Credential Dumping With EDR
Detect OS credential dumping techniques targeting LSASS memory, SAM, and NTDS using EDR telemetry, Sysmon, and Windows event correlation.
Tags
Updated: 2026-09-17Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Monitor LSASS process access
- Detect credential dumping tools
- Monitor NTDS.dit file access
- Track SAM hive access
- Detect DCSync activity
- Correlate lateral movement events
Inputs
- EDR agent telemetry
- Sysmon ProcessAccess logs
- Windows Security event logs
- Registry auditing logs
Outputs
- Threat hunting report
- Credential compromise impact assessment
Requirements
- EDR agent with LSASS access monitoring
- Sysmon Event ID 10 with LSASS filters
- Windows Security Event ID 4656 and 4663 auditing
- LSASS SACL auditing enabled
- Registry auditing for SAM hive
