How to block SAM, LSA dump through Microsoft Defender for Endpoint

Pierre 0 Reputation points
2024-05-31T14:25:17.97+00:00

Hello,

I am trying to see if the EDR Microsoft Defender for Endpoint or other solutions from Microsoft offer options to block the following hive dump SAM, LSA and optionaly DPAPI. I am aware that suspicious dumps are detected but is there a possibility to block it ?

Regards

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,238 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 29,591 Reputation points Microsoft Employee
    2024-06-04T08:53:57.3733333+00:00

    @Pierre Thank you for reaching out to us, As I understand you are trying to block SAM, LSA dump through MDE, Please refer to this blog - https://jeffreyappel.nl/detect-and-block-credential-dumps-with-defender-for-endpoint-attack-surface-reduction/ detailed explanation has been provided here.

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.