logo

Catching Credential Guard Off Guard

ID: 9e0bf66b-303d-525c-ab04-20ca0d12d3d9

STIX ID: report--9e0bf66b-303d-525c-ab04-20ca0d12d3d9

Feed Name: SpecterOps Blog

Threat Score
80/100

Date Published: 2025-10-23

Date Updated: 2026-04-30

Author: Valdemar Carøe

...
...

**Executive summary:** This research demonstrates practical methods to extract credentials from modern Windows systems protected by Credential Guard by leveraging Remote Credential Guard, reimplementing SSP/Negotiate/Kerberos server flows, and invoking Credential Guard NTLM/Kerberos interfaces (including obtaining crackable NTLMv1 responses); the authors provide a proof-of-concept tool (DumpGuard), discuss multiple attack scenarios and requirements (SPN or machine accounts, SYSTEM in some cases), and offer limited defensive guidance (e.g., monitor LsaCallAuthenticationPackage for specific NTLM challenge responses).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.