Detect Credential Access with Elastic Security
ID: 77ab94aa-d9e0-5b2b-9b53-ab39a0a0cf67
STIX ID: report--77ab94aa-d9e0-5b2b-9b53-ab39a0a0cf67
Feed Name: Elastic Security Labs
This report outlines Elastic Endpoint Security enhancements for detecting credential access, showcasing KQL/EQL queries, correlation of authentication and file/registry events, and built-in behavior protection to flag suspicious access patterns. It provides practical hunting examples and a comprehensive list of monitored sensitive file and registry paths (e.g., DPAPI keys, credential stores, browser data, SSH keys) commonly targeted by credential theft tools, enabling earlier detection with minimal false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
