An EDR alert shows a suspicious process opening lsass.exe with PROCESS_VM_READ rights and extracting authentication material. Which MITRE ATT&CK technique best maps this observed credential-access behavior?
Select an answer to reveal the explanation.
Short Explanation
Think of lsass.exe as the vault where Windows keeps live credential material. If a process reaches in and reads that memory, you're mapping it to OS Credential Dumping: LSASS Memory, not to the command that launched it. The trap is blaming PowerShell or valid accounts when the real behavior is reading the vault.
Full Explanation
The technique is chosen from the observed action, not the tool that executed it. When a process opens the Local Security Authority Subsystem Service process and reads its memory, the analyst maps that behavior to OS Credential Dumping: LSASS Memory, because the credential material is extracted from live authentication data structures rather than from hashes stored on disk. Applying ATT&CK this way keeps the detection logic tied to the tactic and behavior, so response can focus on memory access, process lineage, and credential compromise. Valid Accounts is wrong because it describes use of existing credentials to authenticate, not extraction from process memory. Access Token Manipulation is wrong because it covers stealing or impersonating tokens after they exist, not reading LSASS memory to recover credentials. Command and Scripting Interpreter is wrong because it describes execution of shell or script code, which may accompany the activity but is not the credential-access behavior itself. Exam caveat: if the item asks for the technique mapped to lsass.exe memory reads, select the LSASS Memory subtechnique rather than the parent OS Credential Dumping technique when offered. Operational check: correlate the EDR process-open event for lsass.exe with handle rights, parent process, and subsequent logon anomalies before escalating as credential theft.