Catching Credential Guard Off Guard
ID: 9e0bf66b-303d-525c-ab04-20ca0d12d3d9
STIX ID: report--9e0bf66b-303d-525c-ab04-20ca0d12d3d9
Feed Name: SpecterOps Blog
**Executive summary:** This research demonstrates practical methods to extract credentials from modern Windows systems protected by Credential Guard by leveraging Remote Credential Guard, reimplementing SSP/Negotiate/Kerberos server flows, and invoking Credential Guard NTLM/Kerberos interfaces (including obtaining crackable NTLMv1 responses); the authors provide a proof-of-concept tool (DumpGuard), discuss multiple attack scenarios and requirements (SPN or machine accounts, SYSTEM in some cases), and offer limited defensive guidance (e.g., monitor LsaCallAuthenticationPackage for specific NTLM challenge responses).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
