// REFERENCE
Sysmon 10 — Process access
Log: Sysmon/Operational
High risk
A process opened a handle to another (Sysmon). The star case is access to LSASS with memory-read rights (0x1010/0x1410), the classic signature of credential dumping (Mimikatz and friends). Filter by TargetImage lsass.exe.
Related tools
Work with this in:
Related
1
Sysmon 1 — Process creation 3
Sysmon 3 — Network connection 7
Sysmon 7 — Image (DLL) loaded 8
Sysmon 8 — CreateRemoteThread 11
Sysmon 11 — File created 13
Sysmon 13 — Registry value set
Sysmon 1 — Process creation 3
Sysmon 3 — Network connection 7
Sysmon 7 — Image (DLL) loaded 8
Sysmon 8 — CreateRemoteThread 11
Sysmon 11 — File created 13
Sysmon 13 — Registry value set
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.