logo

The CredDefense Toolkit

ID: fe64dbae-7a84-5f82-965f-d5f35d7cafcb

STIX ID: report--fe64dbae-7a84-5f82-965f-d5f35d7cafcb

Feed Name: Black Hills Infosec Blog

Date Published: 2017-09-27

Date Updated: 2026-04-27

Author: BHIS

...
...

This post introduces the free, open-source CredDefense Toolkit for detecting and preventing common credential-abuse techniques in Active Directory environments. It covers a Windows Password Filter to block weak choices (e.g., season-year patterns), a Password Auditing feature leveraging DSInternals to identify reuse and risky settings, Windows Event Forwarding consolidation, Kerberoasting detection using a honey account with SPN and Event ID 4769 parsing, ResponderGuard to discover NBNS/LLMNR spoofers and submit honey credentials for alerting, and password spraying detection via event-log analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.