Sysmon created remote thread to LSASS Process

Sergey Golub 6 Reputation points
2022-02-11T12:00:12.047+00:00

I have researched some ways to detect LSASS Credential Dumping in my infrastructure. I found that Sysmon often create remote thread (EventCode=8) to lsass.exe that looks very suspicious.

Does it legit? Or some malware already injected to my Sysmon agent?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,085 questions
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. User989846-7900 1 Reputation point
    2022-12-14T08:25:52.157+00:00

    Hello,

    Didn't observd your behavior in our lab, but we observerd a process access from sysmon to lsass with granted right 0x1fffff, so it could be possible your unexpected behaviour could also be normal. I would be really interested to understand why you observe this remote thread, or me this process access thought.

    0 comments No comments

  2. Faisalzabd 1 Reputation point
    2023-01-04T03:10:07.34+00:00

    Can you please elaborate more on how did you handle or investigated this ? After you saw sysmon creates remote thread to lsass?

    0 comments No comments