Lslsass
MITRE ATT&CK: S0121 View on attack.mitre.org
Aliases: Lslsass
- Malware type
- credential-stealer
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:35:00
Context
Lslsass is a publicly-available tool that can dump active logon session password hashes from the lsass process.
Detection coverage
- 73 Sigma rules
Malware & tools used
- LSASS Memory (attack-pattern)
Used by threat actors
- APT1 (threat-actor)
Reports & references
- Mandiant — Mandiant Apt1 Report (report)
- MITRE ATT&CK — S0121 (report)