All events
// Operations
Credential Access
Process memory of lsass.exe dumped to disk via comsvcs.dll MiniDump
EVT-FACC0CCritical
Command line
rundll32.exe C:\Windows\System32\comsvcs.dll MiniDump 624 C:\ProgramData\ls.dmp full
Same principal
Other activity for jsmith around this time
| Time | Event | Severity | Host |
|---|---|---|---|
| 2026-09-04 14:17:53Z | Authentication Failure | Low | WIN-DC01 |
| 2026-09-04 14:21:05Z | Authentication Failure | Low | WIN-DC01 |
| 2026-09-04 14:24:17Z | Authentication Failure | Low | WIN-DC01 |
| 2026-09-04 14:27:29Z | Authentication Success | High | WIN-DC01 |
| 2026-09-04 14:30:29Z | Mfa Method Removed | High | WIN-DC01 |
| 2026-09-04 14:33:29Z | User Created | Critical | WIN-DC01 |
| 2026-09-04 14:36:29Z | Process Execution | High | WIN-DC01 |
Record
- Source
- CrowdStrike FalconEndpoint
- Event type
- CREDENTIAL_ACCESS
- Observed
Pivot
Every identifier on this record, as a one-click hunt.