14.2 Investigating Lateral Movement & Credential Access Campaigns
Key Takeaways
Credential access campaigns frequently target the Local Security Authority Subsystem Service (LSASS) via direct memory dumping (mimikatz, procdump, comsvcs.dll), detectable through process handle access rights and suspicious DLL function calls.
Kerberoasting exploits Active Directory Ticket Granting Service (TGS) requests (Event ID 4769) requesting weak RC4-HMAC encryption (0x17) for service accounts, facilitating offline password cracking.
Pass-the-Hash (PtH) and Overpass-the-Hash enable lateral movement via NTLM authentication, manifesting in Windows Security Event Logs as Event ID 4624 (Logon Type 3 - Network) paired with elevated privilege assignments (Event ID 4672).
Adversaries execute remote commands utilizing SMB remote service creation (Event ID 7045 / PsExec), WMI process execution (WmiPrvSE.exe spawning commands), and WinRM sessions (wsmprovhost.exe / ports 5985/5986).
Elastic Security Timeline and the visual event analyzer correlate Windows Security Event Logs, Sysmon/Defend process lineages, and network socket telemetry into an unbroken chain of post-exploitation activity.
The Credential Access & Lateral Movement Campaign Architecture
When an adversary secures an initial foothold on an endpoint—whether through a targeted phishing payload, an exposed edge service, or stolen remote desktop credentials—they rarely land directly on their ultimate objective. High-value data stores, intellectual property repositories, customer databases, and domain controllers are sequestered deep within internal network zones protected by internal firewalls and network segmentation. To traverse from an unprivileged workstation to enterprise crown jewels, an adversary must execute an iterative attack loop: harvest local credentials, escalate privileges, perform internal discovery, and move laterally across systems.
In modern Active Directory (AD) and enterprise environments, identity represents the primary attack surface. By acquiring valid credentials, adversaries transition from conspicuous malware execution to legitimate administrative protocols—a strategy known as "living off the land." Security analysts must understand the precise mechanics of credential theft and lateral movement, the specific Windows Event IDs and ECS telemetry streams they generate, and how to correlate these multi-source artifacts using Elastic Security's Timeline and the visual event analyzer.
In-Depth Credential Access Investigation
1. LSASS Memory Dumping
The Local Security Authority Subsystem Service (lsass.exe) is the core Windows security process responsible for enforcing local security policies, handling user authentications, and storing active credential material in memory (including Kerberos Ticket Granting Tickets [TGTs], NTLM password hashes, and cached plaintext credentials via Security Support Providers like Wdigest).
Adversaries extract credentials from LSASS memory using several distinct mechanisms:
- Direct API Handle Access: Utilities such as
mimikatzornanodumpcall the Windows APIsOpenProcessorDuplicateHandlerequestingPROCESS_VM_READ(0x0010) andPROCESS_QUERY_INFORMATION(0x0400) access rights against thelsass.exeprocess ID. In Sysmon telemetry, this generates Event ID 10 (ProcessAccess) wherewinlog.event_data.TargetImageisC:\Windows\system32\lsass.exeandwinlog.event_data.GrantedAccessincludes0x1010or0x143a. - LOLBin Abuse via
comsvcs.dll: Attackers frequently abuse the native, signed Windows librarycomsvcs.dllto dump LSASS memory without dropping third-party binaries onto disk. The command executesMiniDump(or export ordinal24) viarundll32.exe:
In Elastic Defend telemetry (rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump [lsass_pid] C:\Windows\Temp\lsass.dmp fulllogs-endpoint.events.process-*), this is identified byprocess.name: "rundll32.exe"whereprocess.command_linecontains bothcomsvcs.dllandMiniDump(or24). - Sysinternals
procdump.exe: Attackers leverage Microsoft's legitimate process diagnostic utility to dump LSASS memory:
Theprocdump.exe -ma lsass.exe lsass.dmp-maargument instructs the tool to write a complete memory dump file. Elastic Defend alerts on suspicious process executions referencinglsass.exein conjunction with memory-dumping command-line switches.
2. Kerberoasting Campaigns
Kerberoasting is an Active Directory post-exploitation technique targeting Service Principal Names (SPNs) registered to user accounts. Any authenticated domain user (regardless of privilege level) can query Active Directory for SPNs and request a Kerberos Ticket Granting Service (TGS) ticket from the Domain Controller (KDC) for any target service. The TGS ticket is encrypted with the NTLM password hash of the Active Directory account linked to that SPN. The attacker extracts the ticket from memory and executes offline dictionary or brute-force attacks using tools like Hashcat or John the Ripper to recover the plaintext service account password.
In Elastic Security, Kerberoasting investigations focus on Windows Security Event Log Event ID 4769 (A Kerberos service ticket was requested) on domain controllers:
- Ticket Encryption Type (
winlog.event_data.TicketEncryptionType): Modern Windows environments typically use AES128 (0x11) or AES256 (0x12). Attackers explicitly request ticket downgrade to RC4-HMAC-MD5 (0x17) because RC4 hashes can be cracked offline orders of magnitude faster than AES. - Ticket Options (
winlog.event_data.TicketOptions): Attackers typically request tickets with options0x40810000(forwardable, renewable, canonicalize). - High Request Volume: While individual service ticket requests occur continuously during normal network operations, a Kerberoasting attack generates dozens or hundreds of Event ID 4769 records from a single workstation and user account within a few minutes, querying multiple distinct service accounts.
An ES|QL query to identify Kerberoasting campaigns:
FROM winlogbeat-*
| WHERE winlog.channel == "Security" AND event.code == "4769"
| WHERE winlog.event_data.TicketEncryptionType == "0x17"
AND NOT winlog.event_data.ServiceName LIKE "*$"
| STATS
tgs_count = COUNT(),
unique_services = COUNT_DISTINCT(winlog.event_data.ServiceName)
BY winlog.event_data.TargetUserName, source.ip
| WHERE unique_services > 5
| SORT tgs_count DESC
3. NTDS.dit & SAM Database Harvesting
To compromise the entire domain in a single action, adversaries attempt to copy the Active Directory database file (ntds.dit) from domain controllers, which contains all domain user accounts and password hashes. Because the active file is locked by the operating system, attackers leverage Volume Shadow Copies (vssadmin create shadow /for=C:), ntdsutil.exe ("ac i ntds" "ifm"), or registry hive dumps (reg save HKLM\SAM sam.save and reg save HKLM\SYSTEM system.save). In Elastic Defend, monitoring process executions of vssadmin.exe, ntdsutil.exe, and reg.exe targeting sensitive registry hives provides immediate detection of mass credential theft.
Lateral Movement Investigation Vectors
Once credentials or hashes are harvested, adversaries move across the internal network using several primary protocols and mechanisms:
1. Pass-the-Hash (PtH) and Overpass-the-Hash
- Pass-the-Hash: Attackers authenticate to remote systems over SMB or RPC using an extracted NTLM password hash directly, without needing to crack or know the plaintext password.
- Overpass-the-Hash (Pass-the-Key): Attackers present an NTLM hash to the Kerberos KDC via an AS-REQ (Authentication Service Request) to obtain a valid Kerberos Ticket Granting Ticket (TGT), transitioning their authentication into the Kerberos protocol.
Forensic Telemetry in Elastic Security:
- Windows Security Event ID 4624 (Successful Logon) with:
winlog.event_data.LogonType: "3"(Network Logon: connection across the network to a shared resource).winlog.event_data.AuthenticationPackageName: "NTLM".winlog.event_data.LogonProcessName: "NtLmSsp".winlog.event_data.ElevatedToken: "Yes"or followed immediately by Event ID 4672 (Special Privileges Assigned to New Logon), indicating the newly logged-on user received administrative tokens (SeDebugPrivilege,SeTcbPrivilege).- Source workstation IP (
source.ip) does not match standard administrative jumphosts.
2. Remote Service Creation via SMB (PsExec & sc.exe)
PsExec and similar remote execution tools (such as Impacket's psexec.py or native sc.exe) operate by abusing SMB (TCP port 445) and the Service Control Manager (SCM):
- The attacker connects to the target machine over SMB using administrative credentials.
- The attacker writes an executable binary to an administrative share (
ADMIN$orC$, typically staging inC:\Windows\orC:\Windows\Temp\). - The attacker opens a handle to the Service Control Manager via RPC over the Named Pipe
\pipe\svcctl. - The SCM creates and starts a new Windows service executing the dropped binary under the
NT AUTHORITY\SYSTEMcontext.
Forensic Telemetry in Elastic Security:
- Windows System Event ID 7045 / Security Event ID 4697: "A service was installed in the system".
winlog.event_data.ServiceName: Service name (e.g.,PSEXESVCor pseudo-random names generated by modern attack frameworks).winlog.event_data.ImagePath: Path to the service binary (e.g.,%SystemRoot%\PSEXESVC.exeorC:\Windows\Temp\sysupdate.exe).
- Process Lineage in Process Tree: On the target host,
services.exeappears as the parent process launching the newly registered service executable, which in turn spawnscmd.exeorpowershell.exewith command-line arguments.
3. Remote Management Execution: WMI & WinRM
- Windows Management Instrumentation (WMI): Attackers invoke
wmic /node:[target_host] process call create "cmd.exe /c ..."or execute PowerShellInvoke-WmiMethod. Telemetry revealsWmiPrvSE.exe(WMI Provider Host) spawning command interpreters on the target host. Separately, Microsoft-Windows-WMI-Activity/Operational Event ID 5861 records permanent WMI event subscriptions, a fileless persistence technique. - Windows Remote Management (WinRM): Attackers execute remote commands via PowerShell Remoting (
Enter-PSSession,Invoke-Command) connecting over TCP port 5985 (HTTP) or 5986 (HTTPS). On the target host, the network connection is accepted bysvchost.exe, and commands execute underwsmprovhost.exe(WinRM Provider Host) as the parent process.
Multi-Source Telemetry Correlation in Timeline and Process Tree
Investigating lateral movement requires stitching disparate telemetry sources into a unified chronology. The following forensic walkthrough illustrates how an analyst traces an intrusion from initial credential theft on a workstation to remote command execution on a database server:
+--------------------------------------------------------------------------+
| Step-by-Step Lateral Movement Correlation in Timeline & Process Tree |
| |
| [ Workstation: ws-exec01 (10.0.10.15) ] |
| | |
| +-- (1) 09:14:10: rundll32.exe comsvcs.dll MiniDump (LSASS dumped) |
| | Defend Alert: Suspicious Comsvcs Memory Access |
| | |
| +-- (2) 09:16:02: Outbound network socket to 10.0.20.50:445 (SMB) |
| source.ip: 10.0.10.15 -> destination.ip: 10.0.20.50 |
| |
| [ Database Server: srv-db01 (10.0.20.50) ] |
| | |
| +-- (3) 09:16:03: Security Event ID 4624 (Logon Type 3: Network) |
| | user.name: svc_backup | auth: NTLM |
| | |
| +-- (4) 09:16:04: Security Event ID 4672 (Special Privileges Assigned) |
| | SeDebugPrivilege granted |
| | |
| +-- (5) 09:16:08: System Event ID 7045 (New Service Installed) |
| | ServiceName: DBUpdater |
| | ImagePath: C:\Windows\Temp\dbupdate.exe |
| | |
| +-- (6) 09:16:10: Process Tree Analysis: |
| services.exe (PID 644) |
| \-- dbupdate.exe (PID 4812) |
| \-- cmd.exe /c whoami |
+--------------------------------------------------------------------------+
- Alert Anchor: The investigation begins in Timeline with the High-severity alert on
ws-exec01forrundll32.exedumping LSASS memory at 09:14:10. The analyst pins this event. - Network Pivot: The analyst queries
source.ip: 10.0.10.15 and destination.port: (445 or 135 or 5985)between 09:14:10 and 09:20:00. This reveals an SMB network connection to internal server10.0.20.50at 09:16:02. - Target Host Scoping: Filtering for
host.ip: 10.0.20.50, the analyst identifies Windows Event ID 4624 (Logon Type 3) using NTLM authentication for accountsvc_backup, immediately followed by Event ID 4672 assigning administrative privileges. - Service Installation Verification: Within six seconds of logon, System Event ID 7045 records a new service
DBUpdaterinstalled with binaryC:\Windows\Temp\dbupdate.exe. - Process Tree Confirmation: Opening the visual event analyzer for the new process on
srv-db01, the analyst observesservices.exespawningdbupdate.exe, which spawnscmd.exe /c whoami. The analyst pins these events and attaches them to the active investigation Case.
Reference Table: Windows Event IDs, ECS Mappings & Forensic Significance
The following reference table summarizes the critical Windows Security and System events, ECS field mappings, and forensic significance for investigating credential access and lateral movement:
| Event ID | Description / Attack Vector | Source Channel | Key ECS Fields | Forensic Significance |
|---|---|---|---|---|
| 4624 | Successful Logon (Logon Type 3) | Security | winlog.event_data.LogonType: "3", winlog.event_data.AuthenticationPackageName: "NTLM", source.ip | Confirms remote network authentication across SMB/RPC without an interactive desktop session; hallmark of Pass-the-Hash and remote tooling. |
| 4672 | Special Privileges Assigned | Security | user.name, winlog.event_data.PrivilegeList, host.name | Confirms an authenticated account received administrative rights (SeDebugPrivilege, SeTcbPrivilege), indicating privilege escalation. |
| 7045 / 4697 | New Service Installed (PsExec / Remote SCM) | System (7045) / Security (4697) | winlog.event_data.ServiceName, winlog.event_data.ImagePath, user.name | High-confidence indicator of lateral movement via Service Control Manager; reveals dropped binary path and execution context. |
| 4768 | Kerberos TGT Request (AS-REQ) | Security | winlog.event_data.TargetUserName, winlog.event_data.PreAuthType, source.ip | Pre-auth type 0 indicates missing pre-authentication (AS-REP Roasting); legacy encryption ciphers indicate Overpass-the-Hash attempts. |
| 4769 | Kerberos Service Ticket Request (TGS) | Security | winlog.event_data.ServiceName, winlog.event_data.TicketEncryptionType: "0x17" | High volume of requests with encryption type 0x17 (RC4-HMAC) targeting non-machine SPNs confirms an active Kerberoasting campaign. |
| 10 (Sysmon) | Process Access (LSASS Memory Read) | Sysmon/Operational | process.name, winlog.event_data.TargetImage: "*lsass.exe", winlog.event_data.GrantedAccess | Reveals unauthorized handle opening to LSASS memory with read/query permissions (0x1010, 0x143a) indicative of credential dumping. |
| 5861 | WMI Event Subscription Activity | WMI-Activity/Operational | winlog.event_data.Namespace, winlog.event_data.Query, user.name | Records permanent WMI event consumer registrations, a fileless persistence technique. Remote WMI process creation shows up instead as WmiPrvSE.exe spawning processes. |
During a hunt for credential harvesting on Active Directory domain controllers, an analyst reviews Windows Event ID 4769 (Kerberos Service Ticket Operations). Which combination of telemetry indicators strongly signals an active Kerberoasting campaign?
A single event with TicketEncryptionType set to 0x12 (AES-256) requested by the Domain Controller computer account.
Multiple rapid ticket requests originating from a standard user workstation targeting high-privilege Service Principal Names with TicketEncryptionType set to 0x17 (RC4-HMAC).
An Event ID 4769 event with failure status code 0x6 indicating the target username does not exist.
Repeated requests for Ticket Granting Tickets (TGTs) utilizing Pre-Authentication Type 2 over UDP port 88.
An analyst is triaging an alert indicating suspicious LSASS memory access. Telemetry indicates rundll32.exe was executed with the command line: rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump 724 C:\Windows\Temp\dump.bin full. What type of attack tradecraft does this command represent, and how should it be evaluated?
A credential access technique misusing the native comsvcs.dll library as a Living-off-the-Land Binary (LOLBin) to dump LSASS process memory into a file without dropping third-party binaries.
A legitimate Windows Update routine that compresses kernel memory dump files prior to uploading telemetry to Microsoft.
A defense evasion technique where rundll32.exe is used to patch AMSI (Antimalware Scan Interface) in memory.
A lateral movement technique executing a remote service via the Windows Task Scheduler RPC interface.
An incident responder discovers that an attacker used PsExec to move laterally from a compromised workstation to an internal file server. Which sequence of forensic artifacts in the Elastic Security Timeline and Process Tree confirms this lateral movement vector?
Event ID 4625 (Logon Failure) followed by an outbound DNS query for a dynamic DNS domain on port 53.
An interactive console session in Linux Session View showing the execution of sudo -i followed by cat /etc/shadow.
Windows Event ID 4624 (Logon Type 3) over SMB (port 445), followed by System Event ID 7045 recording a new service installation, with the Process Tree showing services.exe spawning the service executable.
A web server log entry showing HTTP POST /upload.php followed by the creation of a webshell in C:\inetpub\wwwroot.
Sections you finish are checked off in the contents.