The CredDefense Toolkit
ID: fe64dbae-7a84-5f82-965f-d5f35d7cafcb
STIX ID: report--fe64dbae-7a84-5f82-965f-d5f35d7cafcb
Feed Name: Black Hills Infosec Blog
This post introduces the free, open-source CredDefense Toolkit for detecting and preventing common credential-abuse techniques in Active Directory environments. It covers a Windows Password Filter to block weak choices (e.g., season-year patterns), a Password Auditing feature leveraging DSInternals to identify reuse and risky settings, Windows Event Forwarding consolidation, Kerberoasting detection using a honey account with SPN and Event ID 4769 parsing, ResponderGuard to discover NBNS/LLMNR spoofers and submit honey credentials for alerting, and password spraying detection via event-log analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
