Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Play Ransomware – HandleKatz/Nanodump Stealthy LSASS Access

Play Defense Evasion Sentinel
MITRE ATT&CK
LSASS Memory
Data Source
DeviceProcessEvents
Date Added
2026-07-23
Last Updated
2026-07-23
Source
ransomware.live group_tools dataset (play)
What This Detects
Beyond its BYOVD EDR-killer chain, Play uses HandleKatz and Nanodump — two LSASS-dumping tools specifically designed to duplicate the LSASS handle and evade the process-access signatures most EDRs use to flag classic Mimikatz/ProcDump activity.
Query
DeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName has_any ("handlekatz","nanodump") or ProcessCommandLine has_any ("HandleKatz","nanodump")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, AccountName

Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.