LSASS Dump via comsvcs.dll: Defender Detection Guide

Attackers dump LSASS with comsvcs.dll to steal credentials; here’s how to spot rundll32 + MiniDump fast and reliably. 🙂

What the technique is

Adversaries attempt to access credential stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a variety of credential materials in LSASS process memory.

LSASS.exe process memory can be dumped using comsvcs.dll’s MiniDump export (ordinal 24) via rundll32. The dump is often written to a temp path, sometimes disguised with a benign extension.

Exact command executed

LSASS.exe process memory is dumped via comsvcs.dll ordinal 24. Requires sufficient privileges to access LSASS memory.

cmd.exe /Q /c for /f "tokens=1,2 delims= " %%A in ('"tasklist /fi "Imagename eq lsass.exe" | find "lsass""') do rundll32.exe C:\windows\System32\comsvcs.dll, #+000024 %%B C:\Windows\Temp\file.docx full

Breakdown

  • Spins up a quiet, one-shot cmd: /Q hides echo, /c runs the line and exits.
  • Grabs LSASS’s PID: the for /f ... in ('tasklist … | find "lsass"') bit parses tasklist output and stores the 2nd column (PID) in %%B. It’s just – get the PID number for lsass.exe.
  • Dumps the process via comsvcs: rundll32 … comsvcs.dll,#24 %%B … full calls the MiniDump export (ordinal 24) inside comsvcs.dll to write a full memory dump to the path you give (here masquerading as .docx).

Detecting LSASS dump via comsvcs.dll (rundll32)

Visual Sigma mapping

Command-to-rule mapping for the lsass.exe dump via comsvcs.dll (ordinal 24).

Join for free. Practical security bits you can act on the same day. No theory, no fluff.

No spam. Unsubscribe anytime.

Sigma rules that trigger on comsvcs.dll

  1. Potential Obfuscated Ordinal Call Via Rundll32 – catches #,#+000024 style calls
  2. Process Memory Dump Via Comsvcs.DLL – rundll32 invoking comsvcs MiniDump/ordinal 24
  3. Recon Command Output Piped To Findstr.EXE – flags recon where output is piped to findstr

SIEM Detections

These queries were generated by converting the Sigma rule with pySigma backends.

Potential Obfuscated Ordinal Call Via Rundll32

Detects execution of “rundll32” with potential obfuscated ordinal calls

DeviceProcessEvents
| where (FolderPath endswith "\\rundll32.exe" or ProcessVersionInfoOriginalFileName =~ "RUNDLL32.EXE" or ProcessCommandLine contains "rundll32") and (ProcessCommandLine contains "#+" or ProcessCommandLine contains "#-" or ProcessCommandLine contains "#0" or ProcessCommandLine contains "#655" or ProcessCommandLine contains "#656")
(process.executable:*\\rundll32.exe OR process.pe.original_file_name:RUNDLL32.EXE OR process.command_line:*rundll32*) AND (process.command_line:(*#\+* OR *#\-* OR *#0* OR *#655* OR *#656*))

Process Memory Dump Via Comsvcs.DLL

Detects a process memory dump via “comsvcs.dll” using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)

DeviceProcessEvents
| where ((FolderPath endswith "\\rundll32.exe" or ProcessVersionInfoOriginalFileName =~ "RUNDLL32.EXE" or ProcessCommandLine contains "rundll32") and ((ProcessCommandLine contains "comsvcs" and ProcessCommandLine contains "full") and (ProcessCommandLine contains "#-" or ProcessCommandLine contains "#+" or ProcessCommandLine contains "#24" or ProcessCommandLine contains "24 " or ProcessCommandLine contains "MiniDump" or ProcessCommandLine contains "#65560"))) or ((ProcessCommandLine contains "24" and ProcessCommandLine contains "comsvcs" and ProcessCommandLine contains "full") and (ProcessCommandLine contains " #" or ProcessCommandLine contains ",#" or ProcessCommandLine contains ", #" or ProcessCommandLine contains "\"#"))
((process.executable:*\\rundll32.exe OR process.pe.original_file_name:RUNDLL32.EXE OR process.command_line:*rundll32*) AND ((process.command_line:*comsvcs* AND process.command_line:*full*) AND (process.command_line:(*#\-* OR *#\+* OR *#24* OR *24\ * OR *MiniDump* OR *#65560*)))) OR ((process.command_line:*24* AND process.command_line:*comsvcs* AND process.command_line:*full*) AND (process.command_line:(*\ #* OR *,#* OR *,\ #* OR *\"#*)))

Recon Command Output Piped To Findstr.EXE

Detects the execution of a potential recon command where the results are piped to “findstr”. This is meant to trigger on inline calls of “cmd.exe” via the “/c” or “/k” for example. Attackers often time use this technique to extract specific information they require in their reconnaissance phase.

DeviceProcessEvents
| where (ProcessCommandLine contains "ipconfig" and ProcessCommandLine contains "|" and ProcessCommandLine contains "find") or (ProcessCommandLine contains "net" and ProcessCommandLine contains "|" and ProcessCommandLine contains "find") or (ProcessCommandLine contains "netstat" and ProcessCommandLine contains "|" and ProcessCommandLine contains "find") or (ProcessCommandLine contains "ping" and ProcessCommandLine contains "|" and ProcessCommandLine contains "find") or (ProcessCommandLine contains "systeminfo" and ProcessCommandLine contains "|" and ProcessCommandLine contains "find") or (ProcessCommandLine contains "tasklist" and ProcessCommandLine contains "|" and ProcessCommandLine contains "find") or (ProcessCommandLine contains "whoami" and ProcessCommandLine contains "|" and ProcessCommandLine contains "find")
process.command_line:(*ipconfig*\|*find* OR *net*\|*find* OR *netstat*\|*find* OR *ping*\|*find* OR *systeminfo*\|*find* OR *tasklist*\|*find* OR *whoami*\|*find*)

Thanks to @cyb3rops, @frack113, Modexp, @nas_bench, and @swachchhanda for publishing the awesome Sigma rules and helping the community.

Known in-the-wild incidents

A compact, source-linked index of public reports where LSASS dumping via comsvcs.dll appears in real intrusions.

Source Title Source (with link) Publish Date
UAT-7237 targets Taiwanese web hosting infrastructure Cisco Talos 15 Aug, 2025
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira The DFIR Report 5 Aug, 2025
Inside a Real Ransomware Attack: What Happened and How Solis Security 9 Jul, 2025
Credential Theft: Expanding Your Reach Huntress 8 Apr, 2025

References

Thanks for reading. Feel free to connect with me on or LinkedIn for any suggestions or comments.

For more updates and exclusive content, subscribe to our newsletter. Stay sharp. Keep defending.😊

Join for free. Practical security bits you can act on the same day. No theory, no fluff.

No spam. Unsubscribe anytime.

keyboard_arrow_up