Endpoint Detection and ResponseIntermediateFree, no sign-up
Credential theft: LSASS memory access
A case from the EDR Investigation Lab
Briefing
An endpoint sensor at a fictional ledger company sees something unsigned read the memory of the process that holds every logged-on credential. The detection card gives you a four-process tree. The case gives you the full afternoon of endpoint telemetry: process, file, registry, image-load, network and sensor events. Reconstruct the chain from a document to credential theft and decide what to contain.
549 events7 log sourcesabout 35 min
Solve this case
Opens the lab with this case selected. Graded in the browser; nothing to install.
What you will practise
- Reading a process tree the way an EDR console shows it
- Linking file, registry and image-load telemetry to the process that caused it
- Telling a true credential-access detection from noisy admin tooling
- Choosing containment that stops the attacker without destroying evidence
Maps to these certifications
GCIHCySA+CEH
Log sources in the corpus
EDR Process · EDR File · EDR Registry · EDR ImageLoad · EDR Network · EDR Sensor · Windows Security
How a case works
- Read the briefing: the alert as the analyst received it, the environment and the time window.
- Work the console: search, filter and pivot across every source; open raw lines; pin evidence.
- Fill the investigation form and write a short executive summary. Hints are available and cost points.
- Get graded per item with the evidence behind each answer, then share your result card.