A SOC analyst reviews EDR telemetry showing an unapproved process requesting PROCESS_VM_READ and PROCESS_QUERY_INFORMATION access to lsass.exe immediately before a remote RDP logon. Which risk should the analyst prioritize?
Select an answer to reveal the explanation.
Short Explanation
Think of lsass.exe like the hotel safe holding session tickets. If a random process suddenly asks to read it, you’re likely looking at credential dumping or injection. Don’t chase the RDP logon first; map the memory access to stolen credentials.
Full Explanation
Windows isolates authentication material in the Local Security Authority Subsystem Service, so requests for handle rights such as PROCESS_VM_READ or PROCESS_QUERY_INFORMATION against lsass.exe are strong indicators that an attacker is attempting to read credentials, tokens, or secrets from memory. Because those rights allow reading or querying process memory, the behavior maps directly to credential-access risk and often precedes reuse of stolen identities, so the analyst should prioritize containment and memory preservation. A file-staging condition would point to exfiltration preparation rather than direct access to an authentication process, while scheduled-task creation would represent persistence through a new execution trigger. SMB session hijacking or remote logon patterns can support lateral movement, but the decisive indicator here is the anomalous memory-read permission on the protected process, not the transport used afterward. Exam caveat: CompTIA expects mapping of process-memory access to credential-theft risk before broader incident phases. Operational check: isolate the endpoint, preserve volatile memory and EDR artifacts, and correlate the requesting process with command-line, parent-child, and authentication logs, including source IP and Kerberos tickets.