Detecting Credential Dumping in CrowdStrike Falcon Telemetry
Why this matters
Once an attacker has code execution on a Windows host, the next move is almost always to steal credentials from memory — dump LSASS, run Mimikatz, and reuse the harvested hashes and tickets to move laterally. CrowdStrike Falcon records the tool execution, but the raw ProcessRollup2 and SuspiciousActivity stream is enormous, and a pipeline built around IP reputation and web paths has nothing to grab onto in a host-only event. That gap is exactly where credential dumping hides in endpoint telemetry: the event is present, correctly logged, and scored near zero by naive tooling.
Indicators to look for in Falcon telemetry
event_simpleName: SuspiciousActivityorDetectionSummaryEventwith anImageFileNamenaming a known credential-theft tool (our sample:C:\Temp\mimikatz.exe)- A
DetectNamesuch asCobalt Strike Beaconon aDetectionSummaryEvent, indicating post-exploitation tooling on the same host - A
NetworkConnectIP4event to a non-CDN external IP on an unusual port (our sample beacons to185.220.101.42:4444) from the sameaidshortly before or after the dump - A
UserLogonFailed2withSubjectUserName: ANONYMOUS LOGONagainst a privileged account — a lateral-movement probe using stolen material SHA256HashDatavalues on the offending process that resolve to a known-malicious sample in hash reputation feeds
How LogTriage detects this
The Falcon FDR parser normalizes each event by event_simpleName: SuspiciousActivity and DetectionSummaryEvent become 403s, ImageFileName becomes the event’s path, and RemoteAddressIP4 and SHA256HashData feed enrichment. On top of that, LogTriage runs a host-attack signature set specifically because EDR events carry no UA/ASN/path signal — a Mimikatz image name matches the offensive-security-tool signature and floors the event’s risk score to 90 (“credential theft / C2”), and an event referencing lsass floors to 80 (“LSASS access — OS credential dumping, T1003.001”). These floors are independent of threat intelligence, so the dump is scored high even when the tool talks to no external IP. Where the same host also beacons out — our sample’s 185.220.101.42 is a confirmed Tor-exit IOC — the C2 event floors to 75 in parallel, corroborating the compromise. The published Sigma rule LTR-0003, Sysmon LSASS credential dumping, encodes the equivalent LSASS-access logic for the Sysmon source.
Detection / evidence checklist
- Find every
SuspiciousActivity/DetectionSummaryEventon the host and note theImageFileNameandDetectNamefor each - Confirm whether LSASS was the access target or whether a named tool (Mimikatz, Cobalt Strike) ran — both are credential-theft signals
- Pull the
SHA256HashDatafor the offending processes and check them against hash reputation feeds - Correlate any
NetworkConnectIP4from the sameaidto scope command-and-control and possible exfiltration - Treat every credential reachable from that host as exposed — rotate account passwords and Kerberos keys, do not just kill the process
- Isolate the host before the harvested credentials are used for lateral movement
Frequently Asked Questions
- Why does a Mimikatz process alone floor the risk score, without any threat-intel match?
- Endpoint telemetry carries no user-agent, ASN, or web-path signal, so the IP-centric enrichment pipeline would score a Mimikatz execution near zero on its own. LogTriage adds a curated host-attack signature set that matches tool names and behaviors — Mimikatz, LSASS access, process injection, encoded PowerShell — against the normalized operation and target fields and applies a risk floor of 70 to 90. A Mimikatz image name floors the event to 90 regardless of what the additive score was.
- Does the CrowdStrike parser read the process command line?
- Not currently. The FDR parser uses ImageFileName as the process path, so it catches a named tool like mimikatz.exe but does not capture a benign-looking binary invoked with a malicious command line. For command-line-level detection of encoded PowerShell, Sysmon EventID 1 (which does carry CommandLine) is the stronger source; see the Sysmon guide.
- What is the difference between a DetectionSummaryEvent and a SuspiciousActivity event?
- DetectionSummaryEvent is Falcon's own verdict — the agent already flagged the behavior, and carries fields like DetectName, Severity, Tactic, and Technique. SuspiciousActivity is a lower-confidence behavioral signal. Both map to a 403 in LogTriage. In our sample the Mimikatz execution arrives as a SuspiciousActivity while the Cobalt Strike beacon arrives as a DetectionSummaryEvent.
- Which FDR fields does LogTriage use to score a credential-dumping event?
- event_simpleName drives the base status (SuspiciousActivity and DetectionSummaryEvent become 403), ImageFileName becomes the path the host-attack signatures match against, RemoteAddressIP4 feeds threat-intel enrichment, and SHA256HashData feeds hash reputation lookups against MalwareBazaar when enabled.
Related Resources
See this detection run on a real report
Try the live demo with a pre-loaded malicious log set — no signup required — or upload your own log file and get a full AI-reviewed threat report in minutes.