Index / Techniques / LSASS Credential Dumping
Technique Record · T1003.001

LSASS Credential Dumping

Publicly-reported instances of LSASS Credential Dumping bypassing endpoint security products. Maintained on the same basis for every technique in the Index.

4
recorded bypasses
2
products affected

Products recorded as bypassed by LSASS Credential Dumping

ProductEntriesHigh-confidenceMost recent
Microsoft 332026-05-13
Google 112026-05-06

All entries

ProductConfidenceDisclosedSource
Microsoft high 2026-05-13theregister.com record →
Google high 2026-05-06darkreading.com record →
Microsoft high 2026-04-27www.persistent-security.net record →
Microsoft high 2025-06-13undercodetesting.com record →

Counts reflect distinct publicly-reported events on record; absence of an entry means no confirmed public report is on file.