Skeleton Key Malware Detected in Domain Controller Memory
Memory analysis of domain controller DC-PRIMARY detected patching of NTLM authentication in the LSASS process memory consistent with the Mimikatz skeleton key module. This implant allows any account to authenticate with a single master password while also accepting the original password. Detection occurred through behavioral monitoring of processes accessing LSASS memory; the skeleton key provides persistent domain-wide authentication bypass requiring immediate DC remediation.