In a hybrid SOC, EDR telemetry shows a process opening lsass.exe and reading its memory to extract credentials. You need classify this observed behavior in MITRE ATT&CK for an incident report. Which classification best describes what you observed?
Select an answer to reveal the explanation.
Short Explanation
Think of MITRE ATT&CK like a filing cabinet: tactics are the big drawers, techniques are folders, and sub-techniques are the exact paper inside. Your LSASS memory read is not just credential access—it is the precise sub-technique under that drawer. You want the label that tells the reader exactly what happened, not just the broad goal.
Full Explanation
MITRE ATT&CK organizes adversary behavior into tactics, techniques, and sub-techniques. A tactic answers why the adversary performed an action, such as credential access, while a technique describes how they achieved it, and a sub-technique narrows that method to a specific implementation. Reading lsass.exe memory to harvest secrets is a specific credential-theft method under OS Credential Dumping, so the analyst should classify it as a credential access sub-technique. A tactic label would be too broad because it names the adversary objective rather than the observed method. A defense evasion technique would be wrong because the observed action is aimed at obtaining credentials, not hiding activity or removing artifacts. A collection sub-technique would be wrong because collection focuses on gathering data from systems, not extracting authentication material from protected process memory. A tactic-level behavior description would also be insufficient for reporting, since it would hide the actionable detail needed to tune detections and correlate similar incidents. Exam caveat: Do not confuse the credential access tactic with the OS Credential Dumping technique or the LSASS Memory sub-technique. Operational check: Compare the alert against the ATT&CK technique and sub-technique IDs before adding it to the incident timeline.