Systems Remain Down More Than a Week After Initial Disruption
Luminis Health, the nonprofit system operating Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, confirmed on September 4, 2026, that it "was victim to a cyber incident by an unauthorized criminal actor" [1]. As of that update, the organization's phone system and MyChart patient portal remained offline [1]. The virtual urgent care platform CareConnectNow was also unavailable. Luminis Health has not published a restoration timeline [1], and no ransomware or data extortion group has publicly claimed responsibility for the attack [6].
The health system serves a large population across two Maryland counties through its hospitals and more than 100 care locations. Both affected hospitals remain open and treating patients [1][3], but certain appointments have been rescheduled [6], and ambulances carrying noncritical patients have been rerouted away from the emergency departments at both facilities according to a statewide monitoring system [3].
Timeline: Disruption Preceded Public Disclosure by at Least One Day
Luminis Health posted its first public acknowledgment on Facebook on the evening of Tuesday, September 1, 2026 [7]. The online patient portal was confirmed down as of 7:30 p.m. that evening [7].
Reporting from Hoodline, citing Eye On Annapolis, indicates that widespread outages had already begun the previous day, Monday, August 31, with staff reportedly sent home and networks going dark [4]. If accurate, this timeline suggests at least a one-day gap between internal disruption and public disclosure [4]. Luminis Health has not stated when the underlying unauthorized activity began or when it was first detected internally [8].
The more detailed incident update, posted to the Luminis Health website, carries a timestamp of September 4, 2026, at 5:30 p.m. [1]. That update introduced a dedicated patient helpline (443-222-0193) with extended hours through the Labor Day holiday weekend: Saturday, September 5 from 8 a.m. to 5 p.m., Sunday, September 6 from 8 a.m. to 5 p.m., and Monday, September 7 from 8 a.m. to 1 p.m. [1]. Regular helpline hours are Monday through Friday, 8 a.m. to 5 p.m. [1].
Systems Confirmed Unavailable
Based on statements from Luminis Health and reporting from multiple outlets, the following systems have been confirmed offline:
- Phone system (organization-wide) [1]
- MyChart (patient-facing portal for records, messaging, appointments, prescription refills, and video visits) [1]
- CareConnectNow (virtual urgent care platform serving patients across Maryland)
- Electronic patient records (staff at Anne Arundel Medical Center reverted to paper charts) [2]
A patient at Anne Arundel Medical Center described the environment as "a little bit chaotic," noting that "they were using paper charts for everything, but I didn't feel like it affected my patient care by any means" [2].
Attribution and Data Exposure Status
No group has claimed responsibility [6]. Luminis Health describes the actor only as "an unauthorized criminal actor" [1]. The organization has not identified the incident as ransomware. It has not disclosed the method of access or the scope of compromised systems beyond confirming patient-facing platforms are down.
Luminis Health has stated that its investigation into whether patient information was accessed or affected is ongoing [6]. The organization said it would notify individuals "in accordance with applicable legal requirements" if the investigation determines that notification is warranted [6]. As of available reporting, Luminis Health has not confirmed whether patient data was accessed, what categories of information may have been involved, or how many individuals might be affected.
Third-party cybersecurity experts and legal counsel have been engaged to support the investigation and restoration effort [1][3].
Separate Bomb Threat Incident Is Unrelated
Approximately two to three weeks before the cyberattack, both Luminis hospitals were placed on Code Black and lockdown after receiving an unverified phone threat [5]. During that earlier incident, EMS could not transport patients to Anne Arundel Medical Center while the Code Black was in effect, and Doctors Community Medical Center's emergency department remained in lockdown with an increased police presence [5]. Luminis Health confirmed at the time that the threat was unverified and that "contrary to many rumors floating around on social media, there was no gunman on the Annapolis campus" [5].
Some reporting has conflated these two events. No confirmed link exists between the phone threat and the subsequent cyberattack based on available public information.
Maryland Healthcare Sector: Recurring Target
This is not the first time a Maryland health system has experienced significant cyber disruption. Saint Agnes Hospital in Baltimore, part of the Ascension health system, was struck by an attack in May 2024. Nurses reported losing access to electronic patient records and reverting to fax machines and paper spreadsheets [3]. A separate ransomware attack hit Frederick Health in January 2025, resulting in ambulance diversions and emergency-admission restrictions. Luminis Health has not reported restrictions at that scale, but the ambulance rerouting of noncritical patients and the loss of electronic records follow a similar operational pattern [3].
A class action investigation has been initiated related to the Luminis breach, focused on whether the health system's disclosures and data protection practices met legal requirements [8].
Implications for Similarly Sized Health Systems
Luminis Health's footprint, serving patients across multiple counties through its hospitals and more than 100 care locations, is representative of mid-size nonprofit health systems throughout the United States. Several operational characteristics of this incident are instructive for comparable organizations.
First, the loss of the phone system alongside electronic health records and patient portals created a compounding effect. Patients could not call to confirm appointments, could not check MyChart, and could not access virtual urgent care through CareConnectNow [1]. The single dedicated helpline became the sole point of contact for the system's patient population [1][3].
Second, the disclosure gap between the reported August 31 operational disruption and the September 1 public statement [4][7] is a common pattern in healthcare cyber incidents but carries real consequences. Patients arriving at facilities during that window may not have known about system limitations. Health systems that lack pre-established communication playbooks for cyber incidents will likely face the same delay.
Third, the absence of a restoration timeline more than a week after the initial disruption is consistent with incidents that require full forensic imaging of affected systems before recovery can begin. MyChart is a product of Epic Systems; its presence at Luminis Health indicates Epic is the underlying EHR platform. Organizations relying on a single electronic health record platform face total portal loss during such events.
Red Sheep Assessment
Confidence: Moderate
The absence of a public ransomware claim more than a week after the initial disruption is notable but not conclusive. Several possibilities exist. The responsible actor may be conducting private extortion negotiations, a tactic that has become more common as groups attempt to avoid law enforcement attention drawn by public leak sites. Alternatively, the incident may involve a different class of intrusion, such as credential-based access leading to data theft without encryption, which would explain the system takedowns (likely initiated by Luminis Health's own containment actions) without a corresponding ransomware payload.
The fact that Luminis Health has not characterized the incident as ransomware, combined with the early decision to take systems offline and reportedly send staff home [4], is consistent with a containment-driven shutdown rather than an encryption event that forced systems down. This distinction matters because containment shutdowns can sometimes allow faster recovery of unaffected segments, but they also indicate that the organization's security team may have detected lateral movement or data staging that warranted broad network isolation.
The separate, unrelated bomb threat incident [5] occurring weeks before the cyberattack is likely coincidental. Defenders at peer institutions should track social engineering via phone threats as a potential reconnaissance or distraction method in coordinated attack campaigns. No evidence supports that interpretation here; it is mentioned strictly as a pattern to monitor.
Health systems of similar size should treat this incident as a planning reference. The operational impacts -- total portal loss, phone system failure, ambulance rerouting, and paper chart reversion -- represent a realistic worst-case scenario for any organization running centralized IT infrastructure without segmented failover for clinical communications.
Defender's Checklist
- ▢[ ] Verify that clinical communication systems (phone, portal, telehealth) are segmented from the primary EHR network so that a single compromise does not eliminate all patient contact channels simultaneously. Reference HHS 405(d) Health Industry Cybersecurity Practices (HICP), Technical Volume 1, Practice #3 (Asset Management) and Practice #4 (Network Management) for healthcare-specific network segmentation guidance.
- ▢[ ] Confirm that your organization has a pre-drafted public communication template for cyber incidents, with a target disclosure window of under 24 hours from operational impact, to reduce the gap between internal disruption and patient notification. Test this template against your state's breach notification statute timelines.
- ▢[ ] Test paper-based clinical workflow procedures at least annually, referencing Joint Commission Emergency Management (EM) standards, specifically EM.02.02.03 (procedures for managing utilities failures) and EM.02.02.09 (procedures for clinical activities during emergencies). Luminis staff reverted to paper charts [2]; organizations that have not drilled this process will face longer stabilization periods.
- ▢[ ] Review ambulance diversion protocols with your regional EMS coordination authority (in Maryland, MIEMSS) to ensure automatic rerouting triggers are documented and tested before an incident occurs [3].
- ▢[ ] Assess whether your MyChart or equivalent patient portal deployment includes an independent status page or alternate notification mechanism (e.g., SMS blast capability via a separate communications provider such as Everbridge or Twilio, hosted on infrastructure independent of the primary network) that remains functional during a primary system outage. Pre-load patient contact lists into the alternate notification system on a scheduled export basis.
References
[1] https://www.luminishealth.org/en/cybersecurity-incident-update?language_content_entity=en
[2] https://www.capitalgazette.com/2026/09/03/cybersecurity-incident-luminis-health-electronic-records/
[3] https://www.thebanner.com/community/public-health/luminis-cybersecurity-event-5D66ANTI7JH6PMTYACJ4VKKKIQ/
[4] https://hoodline.com/2026/09/luminis-health-hospitals-hit-by-cyberattack-portals-down-days-after-bomb-threat/
[5] https://www.eyeonannapolis.net/2026/08/unverified-threat-prompts-lockdown-at-luminis-health-hospitals/
[6] https://www.hipaajournal.com/luminis-health-jeffrey-reuben-well-child-horizon-eye-care-data-breaches/
[7] https://foxbaltimore.com/news/local/luminis-health-facilities-cyberattack
[8] https://www.classaction.org/data-breach-lawsuits/luminis-health-september-2026
Event Timeline
Timeline
Hunt Guide: Healthcare Sector Cyberattack - Luminis Health Operational Disruption Pattern
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If a criminal actor is conducting a healthcare-targeted intrusion similar to the Luminis Health incident in our environment, we expect to observe indicators of lateral movement, credential abuse, mass system disruption across clinical and communications infrastructure, data staging for exfiltration, and potential ransomware precursor activity in endpoint, network, and authentication logs.
Intelligence Summary: Luminis Health, a nonprofit health system operating two Maryland hospitals and over 100 care locations, confirmed on September 4, 2026, that it was the victim of a cyber incident by an unauthorized criminal actor. The attack disabled the phone system, MyChart patient portal, CareConnectNow virtual urgent care platform, and electronic patient records, forcing staff to revert to paper charts. No ransomware or data extortion group has publicly claimed responsibility, and the responsible group has not been confirmed; the assessment with moderate confidence suggests the incident may involve a containment-driven shutdown rather than an encryption event, potentially indicating credential-based access leading to data theft without a ransomware payload.
Confidence: Moderate | Priority: Critical
Scope
- Networks: All clinical network segments including EHR infrastructure (Epic/MyChart servers), VoIP/phone system networks, patient portal DMZ, telehealth platforms, Active Directory domain controllers, and backup infrastructure. Include VPN concentrators and remote access gateways.
- Timeframe: 30-day retrospective hunt window. The Luminis Health incident showed a potential gap between initial compromise and operational disruption, suggesting adversaries may dwell for days to weeks before taking impactful action.
- Priority Systems: Epic EHR servers and MyChart portal infrastructure, Active Directory domain controllers, VoIP/PBX systems, backup servers and NAS devices, VPN concentrators, jump boxes and administrative workstations, telehealth platform servers
MITRE ATT&CK Techniques
T1078: Valid Accounts (Initial Access / Persistence) [P2]
The source report describes the actor as an unauthorized criminal actor who gained access to Luminis Health systems. The Red Sheep Assessment suggests credential-based access leading to data theft without encryption as a plausible scenario. Healthcare organizations are commonly targeted via compromised VPN credentials, RDP accounts, or stolen Active Directory credentials purchased from initial access brokers.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" (EventCode=4624 OR EventCode=4625) Logon_Type IN (3,10)
| eval hour=strftime(_time,"%H")
| stats count as login_count dc(dest) as unique_hosts values(Logon_Type) as logon_types by src_ip, user, hour
| where login_count > 15 OR unique_hosts > 5
| sort -login_count
| table _time, src_ip, user, login_count, unique_hosts, logon_types
Elastic KQL:
event.code:("4624" OR "4625") AND winlog.event_data.LogonType:("3" OR "10") | Stats by source.ip, user.name
Sigma Rule:
title: Suspicious Multiple Host Login Activity Indicating Credential Abuse
id: a1b2c3d4-e5f6-7890-abcd-ef1234567890
status: experimental
author: RedSheepSec
date: 2026/09/12
description: Detects a single account authenticating to an unusually high number of distinct hosts, which may indicate lateral movement via valid credentials as observed in healthcare sector intrusions.
logsource:
product: windows
service: security
detection:
selection:
EventID:
- 4624
LogonType:
- 3
- 10
condition: selection | count(TargetHostname) by TargetUserName > 10
timeframe: 1h
falsepositives:
- IT administrators performing legitimate maintenance across multiple systems
- Vulnerability scanners using service accounts
- SCCM or software deployment tools
level: high
tags:
- attack.initial_access
- attack.t1078
- attack.lateral_movement
Tune the threshold based on your environment. IT admin accounts and service accounts performing patch management will generate false positives. Baseline normal login patterns per account before deploying. Focus on accounts authenticating from unusual source IPs, especially external or VPN IPs during off-hours.
T1021.001: Remote Desktop Protocol (Lateral Movement) [P2]
The Luminis Health incident involved broad lateral access across clinical systems (EHR, phone, portal, telehealth). RDP is one of the most common lateral movement vectors in healthcare ransomware and pre-ransomware intrusions. The containment-driven shutdown described in the report suggests defenders detected lateral movement warranting broad network isolation.
Splunk SPL:
index=winevent sourcetype="XmlWinEventLog:Security" EventCode=4624 Logon_Type=10
| eval hour=strftime(_time,"%H")
| stats count as rdp_sessions dc(src_ip) as unique_sources by dest, user
| where rdp_sessions > 10 OR unique_sources > 3
| sort -rdp_sessions
| table dest, user, rdp_sessions, unique_sources
Elastic KQL:
event.code:"4624" AND winlog.event_data.LogonType:"10" AND NOT source.ip:("10.0.0.0/8" OR "172.16.0.0/12" OR "192.168.0.0/16")
Sigma Rule:
title: Unusual RDP Lateral Movement Pattern in Healthcare Environment
id: b2c3d4e5-f6a7-8901-bcde-f12345678901
status: experimental
author: RedSheepSec
date: 2026/09/12
description: Detects RDP logon events from unusual sources or in unusual volumes that may indicate lateral movement preceding a containment shutdown scenario similar to the Luminis Health incident.
logsource:
product: windows
service: security
detection:
selection:
EventID: 4624
LogonType: 10
condition: selection | count() by SourceNetworkAddress > 5
timeframe: 30m
falsepositives:
- IT help desk using RDP for remote support
- Citrix or VDI infrastructure generating RDP sessions
level: high
tags:
- attack.lateral_movement
- attack.t1021.001
Correlate with Sysmon network connection events for RDP port 3389. In healthcare environments, clinical workstations rarely initiate RDP sessions to other workstations. Focus on workstation-to-workstation RDP rather than admin jump-box to server patterns.
T1486: Data Encrypted for Impact (Impact) [P2]
While Luminis Health has not confirmed ransomware and no group has claimed responsibility, the operational pattern (total portal loss, EHR downtime, phone system failure) is consistent with ransomware or pre-ransomware activity. The Red Sheep Assessment notes this could be a containment shutdown rather than encryption, but defenders should hunt for both scenarios. Healthcare ransomware typically targets file shares, database servers, and backup infrastructure.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=11
| rex field=TargetFilename "(?<extension>\.[^.]+$)"
| where match(extension, "\.(encrypted|locked|crypt|enc|ransom|ryk|lockbit|blackcat|alphv|royal|akira|rhysida|medusa|bianlian|blackbasta)$")
| stats count as file_count dc(TargetFilename) as unique_files by Computer, Image
| where file_count > 50
| sort -file_count
| table _time, Computer, Image, file_count, unique_files
Elastic KQL:
event.code:"11" AND file.extension:("encrypted" OR "locked" OR "crypt" OR "enc" OR "ransom" OR "lockbit" OR "blackcat" OR "alphv" OR "royal" OR "akira" OR "rhysida" OR "medusa" OR "bianlian" OR "blackbasta")
Sigma Rule:
title: Ransomware File Extension Indicator on Healthcare Systems
id: c3d4e5f6-a7b8-9012-cdef-123456789012
status: experimental
author: RedSheepSec
date: 2026/09/12
description: Detects creation of files with extensions commonly associated with ransomware encryption, relevant to healthcare sector targeting patterns.
logsource:
product: windows
category: file_event
detection:
selection:
EventID: 11
TargetFilename|endswith:
- '.encrypted'
- '.locked'
- '.crypt'
- '.enc'
- '.ransom'
condition: selection
falsepositives:
- Legitimate encryption tools such as VeraCrypt or 7-Zip creating encrypted archives
- Backup software creating encrypted backup files
level: critical
tags:
- attack.impact
- attack.t1486
This is a broad detection. Tune by excluding known backup encryption tools and legitimate file encryption utilities. Combine with volume-based anomaly detection: a single process creating hundreds of files with new extensions in minutes is a strong ransomware indicator.
T1490: Inhibit System Recovery (Impact) [P1]
Ransomware actors targeting healthcare commonly delete Volume Shadow Copies and disable Windows Recovery features before deploying encryption payloads. This technique is a strong precursor indicator and may have preceded the broad system outage observed at Luminis Health if ransomware was involved.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(CommandLine, "(?i)(vssadmin\s+(delete|resize)\s+shadows|wmic\s+shadowcopy\s+delete|bcdedit\s+/set\s+\{default\}\s+(recoveryenabled\s+no|bootstatuspolicy\s+ignoreallfailures)|wbadmin\s+delete\s+(catalog|systemstatebackup))")
| stats count by Computer, User, CommandLine, ParentCommandLine, ParentImage
| table _time, Computer, User, CommandLine, ParentCommandLine, ParentImage
Elastic KQL:
process.command_line:(*vssadmin*delete*shadows* OR *wmic*shadowcopy*delete* OR *bcdedit*recoveryenabled*no* OR *wbadmin*delete*catalog*)
Sigma Rule:
title: Shadow Copy Deletion or Recovery Inhibition
id: d4e5f6a7-b8c9-0123-defa-234567890123
status: stable
author: Florian Roth
date: 2019/06/01
modified: 2026/09/12
description: Detects deletion of shadow copies or disabling of recovery options, a common ransomware precursor technique.
references:
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml
logsource:
product: windows
category: process_creation
detection:
selection_vssadmin:
CommandLine|contains|all:
- 'vssadmin'
- 'delete'
- 'shadows'
selection_wmic:
CommandLine|contains|all:
- 'wmic'
- 'shadowcopy'
- 'delete'
selection_bcdedit:
CommandLine|contains|all:
- 'bcdedit'
- 'recoveryenabled'
- 'no'
selection_wbadmin:
CommandLine|contains|all:
- 'wbadmin'
- 'delete'
condition: selection_vssadmin or selection_wmic or selection_bcdedit or selection_wbadmin
falsepositives:
- Legitimate administrative cleanup of shadow copies
level: critical
tags:
- attack.impact
- attack.t1490
Attribution: Florian Roth, SigmaHQ (adapted)
This detection has very few legitimate false positives in healthcare environments. Any shadow copy deletion on clinical systems (EHR servers, file shares, domain controllers) should trigger immediate investigation. Combine with process tree analysis to determine if the parent process is suspicious.
T1048: Exfiltration Over Alternative Protocol (Exfiltration) [P2]
The Luminis Health investigation into whether patient information was accessed or affected is ongoing. The Red Sheep Assessment suggests credential-based access leading to data theft as a plausible scenario. Healthcare data exfiltration often uses alternative protocols including DNS tunneling, HTTPS to cloud storage, or transfers to attacker-controlled infrastructure.
Splunk SPL:
index=corelight sourcetype=corelight_dns
| eval query_len=len(query)
| stats count as dns_queries avg(query_len) as avg_query_length max(query_len) as max_query_length dc(query) as unique_queries by id.orig_h, query
| rex field=query "(?<subdomain>[^.]+)\.(?<domain>[^.]+\.[^.]+)$"
| stats count as total_queries sum(dns_queries) as query_volume avg(avg_query_length) as avg_len by id.orig_h, domain
| where avg_len > 50 AND total_queries > 100
| sort -query_volume
| table id.orig_h, domain, total_queries, query_volume, avg_len
Elastic KQL:
event.dataset:"corelight.dns" AND dns.question.name:* AND NOT dns.question.type:("PTR" OR "SRV")
DNS tunneling detection requires baselining normal query lengths and volumes. Focus on unusually long subdomain labels (over 50 characters) and high query volumes to uncommon domains. Also hunt for large outbound transfers over HTTPS to cloud storage providers (Mega, Dropbox, OneDrive personal accounts) using corelight_http logs.
T1059.001: PowerShell (Execution) [P2]
PowerShell is commonly used by ransomware operators and criminal actors for reconnaissance, lateral movement scripting, credential harvesting, and payload delivery. In healthcare intrusions, PowerShell is frequently used to enumerate Active Directory, disable security tools, and stage data for exfiltration.
Splunk SPL:
index=powershell sourcetype=XmlWinEventLog EventCode=4104
| where match(ScriptBlockText, "(?i)(Invoke-Mimikatz|Invoke-Kerberoast|Get-GPPPassword|Invoke-SMBExec|Invoke-WMIExec|Invoke-DCSync|Get-NetComputer|Get-NetUser|Get-DomainController|Find-LocalAdminAccess|Invoke-ShareFinder|Invoke-FileFinder|Invoke-Portscan|New-PSSession|Enter-PSSession|Set-MpPreference\s+-DisableRealtimeMonitoring|Add-MpPreference\s+-ExclusionPath)")
| stats count by Computer, UserID, ScriptBlockText
| table _time, Computer, UserID, ScriptBlockText
Elastic KQL:
event.code:"4104" AND powershell.script_block_text:(*Invoke-Mimikatz* OR *Invoke-Kerberoast* OR *Get-GPPPassword* OR *Set-MpPreference*DisableRealtimeMonitoring* OR *Add-MpPreference*ExclusionPath* OR *Invoke-DCSync*)
Sigma Rule:
title: Suspicious PowerShell Commands in Healthcare Environment
id: e5f6a7b8-c9d0-1234-efab-345678901234
status: experimental
author: RedSheepSec
date: 2026/09/12
description: Detects PowerShell commands commonly used by ransomware operators and criminal actors during healthcare sector intrusions for credential theft, reconnaissance, and defense evasion.
logsource:
product: windows
category: ps_script
detection:
selection_recon:
ScriptBlockText|contains:
- 'Get-NetComputer'
- 'Get-NetUser'
- 'Get-DomainController'
- 'Find-LocalAdminAccess'
- 'Invoke-ShareFinder'
selection_credential:
ScriptBlockText|contains:
- 'Invoke-Mimikatz'
- 'Invoke-Kerberoast'
- 'Get-GPPPassword'
- 'Invoke-DCSync'
selection_defense_evasion:
ScriptBlockText|contains:
- 'Set-MpPreference'
- 'DisableRealtimeMonitoring'
- 'Add-MpPreference'
- 'ExclusionPath'
condition: selection_recon or selection_credential or selection_defense_evasion
falsepositives:
- Red team exercises
- IT security assessments
level: high
tags:
- attack.execution
- attack.t1059.001
Enable PowerShell ScriptBlock logging (EventID 4104) and Module logging on all endpoints. Clinical workstations running Epic or MyChart clients should rarely execute offensive PowerShell tools. Any detection on a clinical system is high-confidence malicious.
T1003.001: LSASS Memory (Credential Access) [P1]
Credential dumping from LSASS is a critical precursor to lateral movement in healthcare intrusions. The broad scope of the Luminis Health compromise (affecting phone systems, EHR, patient portals, and telehealth simultaneously) suggests the attacker obtained domain-level credentials enabling access across multiple network segments.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=10 TargetImage="*\\lsass.exe"
| where NOT match(SourceImage, "(?i)(csrss\.exe|services\.exe|smss\.exe|wininit\.exe|wmiprvse\.exe|svchost\.exe|mrt\.exe|taskmgr\.exe|lsm\.exe|MsMpEng\.exe|SecurityHealthService\.exe|CrowdStrike)")
| stats count by Computer, SourceImage, GrantedAccess
| table _time, Computer, SourceImage, GrantedAccess, count
Elastic KQL:
event.code:"10" AND winlog.event_data.TargetImage:*lsass.exe AND NOT winlog.event_data.SourceImage:(*csrss.exe OR *services.exe OR *smss.exe OR *wininit.exe OR *MsMpEng.exe OR *CrowdStrike*)
Sigma Rule:
title: LSASS Memory Access by Non-System Process
id: f6a7b8c9-d0e1-2345-fabc-456789012345
status: stable
author: Florian Roth
date: 2019/10/16
modified: 2026/09/12
description: Detects process access to LSASS memory by non-standard processes, indicating potential credential dumping.
references:
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_access/proc_access_win_lsass_memdump.yml
logsource:
product: windows
category: process_access
detection:
selection:
TargetImage|endswith: '\lsass.exe'
GrantedAccess|startswith:
- '0x1010'
- '0x1038'
- '0x1F0FFF'
- '0x1F1FFF'
- '0x1F3FFF'
filter_known:
SourceImage|endswith:
- '\csrss.exe'
- '\wininit.exe'
- '\wmiprvse.exe'
- '\svchost.exe'
- '\MsMpEng.exe'
condition: selection and not filter_known
falsepositives:
- Legitimate security tools performing memory scanning
- Antivirus solutions accessing LSASS
level: critical
tags:
- attack.credential_access
- attack.t1003.001
Attribution: Florian Roth, SigmaHQ (adapted)
Sysmon EventID 10 with TargetImage lsass.exe is one of the highest-fidelity credential theft detections. Ensure your Sysmon configuration includes ProcessAccess logging. Filter legitimate AV and EDR products. Any unknown process accessing LSASS on a clinical workstation or EHR server warrants immediate investigation.
T1570: Lateral Tool Transfer (Lateral Movement) [P2]
The simultaneous impact across phone systems, EHR, patient portal, and telehealth at Luminis Health indicates the attacker moved tools and potentially ransomware payloads across network segments. Hunting for unusual SMB file transfers and PsExec-like activity is critical for detecting this pre-encryption staging.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(Image, "(?i)(psexec|psexesvc|paexec|remcom|csexec)") OR match(CommandLine, "(?i)(\\\\.*\\(admin|c|d)\$|copy.*\\\\|xcopy.*\\\\|robocopy.*\\\\)")
| stats count by Computer, User, Image, CommandLine, ParentImage
| table _time, Computer, User, Image, CommandLine, ParentImage, count
Elastic KQL:
process.name:(psexec* OR psexesvc* OR paexec* OR remcom*) OR process.command_line:(*admin$* OR *\\c$* OR *\\d$*)
Sigma Rule:
title: PsExec or Remote Admin Tool Execution
id: a7b8c9d0-e1f2-3456-abcd-567890123456
status: stable
author: Florian Roth
date: 2022/01/01
modified: 2026/09/12
description: Detects execution of PsExec and similar remote administration tools commonly used for lateral movement in ransomware campaigns targeting healthcare.
references:
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sysinternals_psexec.yml
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith:
- '\PsExec.exe'
- '\PsExec64.exe'
- '\PSEXESVC.exe'
- '\PAExec.exe'
- '\RemCom.exe'
- '\CSExec.exe'
condition: selection
falsepositives:
- Legitimate administrative use of PsExec
- Software deployment tools
level: high
tags:
- attack.lateral_movement
- attack.t1570
Attribution: Florian Roth, SigmaHQ (adapted)
PsExec is widely used for legitimate administration. Tune by whitelisting known admin workstations. In healthcare environments, PsExec should not originate from clinical workstations. Also monitor for renamed PsExec binaries using Sysmon EventID 1 with OriginalFileName field.
T1562.001: Disable or Modify Tools (Defense Evasion) [P1]
Criminal actors targeting healthcare systems commonly disable endpoint protection, Windows Defender, and logging before deploying ransomware or conducting data theft. This defense evasion technique would explain how an attacker could maintain persistence across clinical systems without triggering alerts.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| where match(CommandLine, "(?i)(sc\s+(stop|delete|config)\s+(windefend|mpssvc|wscsvc|securityhealthservice|sense|mbamdaemon|mcshield)|net\s+stop\s+(windefend|mpssvc|mcshield|mbamdaemon)|Set-MpPreference\s+-DisableRealtimeMonitoring\s+\$?true|Uninstall-WindowsFeature\s+-Name\s+Windows-Defender)")
| stats count by Computer, User, CommandLine, ParentImage
| table _time, Computer, User, CommandLine, ParentImage
Elastic KQL:
process.command_line:(*sc*stop*windefend* OR *sc*delete*windefend* OR *net*stop*windefend* OR *Set-MpPreference*DisableRealtimeMonitoring* OR *sc*stop*sense*)
Sigma Rule:
title: Security Tool Service Tampering
id: b8c9d0e1-f2a3-4567-bcde-678901234567
status: experimental
author: RedSheepSec
date: 2026/09/12
description: Detects attempts to stop, delete, or disable security services including Windows Defender, CrowdStrike Falcon (Sense), and other endpoint protection commonly targeted before ransomware deployment.
logsource:
product: windows
category: process_creation
detection:
selection_sc:
CommandLine|contains:
- 'sc stop windefend'
- 'sc delete windefend'
- 'sc stop sense'
- 'sc delete sense'
- 'sc stop mpssvc'
- 'sc stop wscsvc'
- 'sc stop SecurityHealthService'
selection_net:
CommandLine|contains:
- 'net stop windefend'
- 'net stop sense'
- 'net stop mpssvc'
selection_ps:
CommandLine|contains:
- 'Set-MpPreference'
- 'DisableRealtimeMonitoring'
condition: selection_sc or selection_net or selection_ps
falsepositives:
- Legitimate IT operations during endpoint agent upgrades
level: critical
tags:
- attack.defense_evasion
- attack.t1562.001
Any attempt to disable endpoint security on clinical systems is extremely high priority. Correlate with CrowdStrike sensor health data in index=crowdstrike to detect agents going offline. Consider creating a watchlist of critical clinical systems and alerting if their EDR sensors stop reporting.
T1046: Network Service Scanning (Discovery) [P2]
The Luminis Health attacker compromised systems across multiple network segments (phone, EHR, patient portal, telehealth). Network scanning is a likely reconnaissance step to map the healthcare network, identify clinical systems, and discover lateral movement opportunities.
Splunk SPL:
index=corelight sourcetype=corelight_conn
| stats dc(id.resp_p) as unique_ports dc(id.resp_h) as unique_dest_hosts count as conn_count by id.orig_h
| where (unique_ports > 50 OR unique_dest_hosts > 30) AND conn_count > 200
| sort -unique_dest_hosts
| table id.orig_h, unique_ports, unique_dest_hosts, conn_count
Elastic KQL:
event.dataset:"corelight.conn" | Stats by source.ip, destination.port
Network scanning from clinical workstations or medical devices is almost always malicious. Focus on hosts that are not known vulnerability scanners or IT management tools. Cross-reference with asset inventory to identify scanning originating from unexpected network segments such as clinical VLANs or medical device subnets.
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Windows Security Event Logs (EventID 4624, 4625, 4648, 4688) | T1078, T1021.001 | Ensure successful and failed logon events are forwarded to index=winevent. LogonType 10 (RDP) and LogonType 3 (Network) are critical for lateral movement detection. |
| Sysmon (EventID 1, 3, 10, 11) | T1486, T1490, T1003.001, T1570, T1562.001, T1059.001 | Sysmon must be deployed on all Windows endpoints and servers, including EHR servers, clinical workstations, and communications infrastructure. EventID 10 (ProcessAccess) configuration must include lsass.exe targeting. EventID 11 (FileCreate) needed for ransomware file extension detection. |
| PowerShell ScriptBlock Logging (EventID 4104) | T1059.001, T1562.001 | Enable ScriptBlock logging via Group Policy on all Windows systems. Logs should forward to index=powershell. Module logging (EventID 4103) provides additional context. |
| Corelight/Zeek Network Metadata | T1048, T1046 | Corelight sensors must have visibility into inter-VLAN traffic, especially between clinical segments, administrative networks, and DMZ segments hosting patient portals. DNS query logs (corelight_dns) and connection logs (corelight_conn) are critical. |
| CrowdStrike EDR | T1562.001, T1003.001, T1570 | Monitor CrowdStrike sensor health in index=crowdstrike. Agents going offline unexpectedly may indicate security tool tampering. Detection events (crowdstrike:falcon:detections:json) provide additional alerting capability. |
| Firewall/PAN Logs | T1046, T1048, T1021.001 | Palo Alto firewall logs in index=firewall-pan provide inter-zone traffic visibility critical for detecting lateral movement between network segments and data exfiltration attempts. |
Recommendations
- Deploy all P1 detection queries (shadow copy deletion T1490, LSASS credential access T1003.001, and security tool tampering T1562.001) as real-time alerts in Splunk across all clinical and administrative Windows systems, with immediate SOC escalation procedures.
- Deploy P2 behavioral detection queries (credential abuse T1078, RDP lateral movement T1021.001, PowerShell abuse T1059.001, lateral tool transfer T1570, network scanning T1046) as scheduled searches running at 15-minute intervals, generating notable events for analyst triage.
- Conduct a network segmentation assessment to determine whether clinical communications (VoIP/PBX), patient portal infrastructure (Epic MyChart), telehealth platforms, and EHR servers reside on independent network segments with enforced access controls, referencing HHS 405(d) HICP Technical Volume 1 Practice 4.
- Verify that CrowdStrike EDR agents are deployed and reporting on all EHR servers, domain controllers, clinical workstations, and VoIP/PBX servers. Create a sensor health monitoring dashboard in Splunk using index=crowdstrike sourcetype=crowdstrike:inventory:aidmaster to detect agents going offline.
- Test paper-based clinical workflow procedures in coordination with clinical leadership, referencing Joint Commission EM.02.02.03 and EM.02.02.09 standards, to ensure clinical staff can maintain patient care if electronic systems are unavailable.
- Validate that a pre-drafted public communication template exists for cyber incidents with a target disclosure window under 24 hours from operational impact, and ensure an independent notification mechanism (SMS blast capability via Everbridge or equivalent on infrastructure separate from the primary network) is pre-loaded with patient contact lists.
- Review ambulance diversion protocols with regional EMS coordination to ensure automatic rerouting triggers are documented and tested before an incident occurs.
- Implement DNS query logging enrichment in Splunk using the corelight_dns sourcetype to enable DNS tunneling detection, and create a baseline of normal query lengths and volumes per internal host.
Sources
- Luminis Health Cybersecurity Incident Update
- Capital Gazette - Cybersecurity Incident Luminis Health Electronic Records
- The Banner - Luminis Cybersecurity Event
- Hoodline - Luminis Health Hospitals Hit by Cyberattack
- Eye On Annapolis - Unverified Threat Prompts Lockdown at Luminis Health Hospitals
- HIPAA Journal - Luminis Health Data Breaches
- Fox Baltimore - Luminis Health Facilities Cyberattack
- ClassAction.org - Luminis Health September 2026 Data Breach Lawsuits