Bypass Record

LSASS Credential Dumping × Microsoft Windows Hello for Business

A publicly-reported instance of LSASS Credential Dumping bypassing Microsoft Windows Hello for Business, recorded with its original source. Factual record; no assessment of any specific deployment.

Product
Microsoft Windows Hello for Business
Technique
LSASS Credential Dumping
MITRE ATT&CK
T1003.001
Confidence
High
Severity
High
Status
poc
Disclosed
2026-08-07
Config / version noted
Not stated

Provenance

Reported as

abuses Windows Hello for Business (WHFB) keys to authenticate to Microsoft Entra ID without the victim's PIN, biometrics, or password

Mechanism

Attackers with access to an active Windows session export WHFB key material (likely via LSASS or DPAPI) and use it to authenticate to Entra ID services, bypassing the need for PIN or biometric verification. This defeats the passwordless authentication assurance of WHFB.

Detection & mitigation

Monitor for suspicious access to LSASS or DPAPI where WHFB keys are stored, such as unexpected process access or credential export tools. Enforce conditional access policies and investigate anomalous Entra ID authentications lacking MFA or biometric prompts.

LSASS Credential Dumping has also been recorded against

This is a record of a publicly-reported event, not an assessment of any specific organization's deployment. Detection and mitigation notes are drawn from the cited source. Where the source is silent, fields are omitted.