Overview
On Windows this means reading LSASS memory or the SAM database; on Linux, /etc/shadow and keyrings; in browsers, the encrypted password store paired with the user's DPAPI key.\nThe value comes from reuse: cached domain hashes and saved cloud tokens open doors far beyond the stolen machine.\nLSA protection, Credential Guard, and hardware-backed tokens raise the cost considerably.
Indicators of Compromise
Signals that suggest this is present on a system.
- Unnamed or renamed security-tool processes reading LSASS
- Unexpected access to /etc/shadow or registry hives
- Massive numbers of NTLM authentications after a dump
Controls that stop it
-
Enforce Multi-Factor Authentication
Require a second factor on every login, and make it phishing-resistant where you can: passkeys, FIDO2 security keys or certificate-based authentication. Push-based MFA is meaningfully better than no second factor, but it is still vulnerable to fatigue and real-time relay attacks. Apply it first to remote access, email and administrative accounts.
-
Apply Least Privilege Everywhere
Give accounts, processes, tokens and service principals the minimum permissions needed, for the minimum time. Review admin rights and service accounts on a schedule, remove standing privilege, and prefer short-lived credentials over long-lived keys. Deny by default so a missing check fails closed rather than open.