Dumping LSASS to a file named lsass.dmp is not exactly stealthy tradecraft anymore. However, I was reading the analysis of the BravoX ransomware group from my colleague Florian Scheiber, and he writes:
A memory dump of the lsass.exe process (lsass.dmp) was created on a server, hardly a subtle move, but when there is no one watching, there is no judge. [1]
I checked our case data, and this is more common than one might assume ๐ซฃ.
Elastic has had a detection rule since December 2020 [2]. Would your detection stack catch it?
[1] https://labs.infoguard.ch/posts/bravox/bravox/
[2] https://github.com/elastic/detection-rules/blob/f8fdc29f73df76b58038695769547cbd002dbcc0/rules/windows/credential_access_lsass_memdump_file_created.toml









