Account Credentials Theft in Domain Environments Detected by EDR
ID: b57e186a-8861-5c8b-b639-3d8e44bbc389
STIX ID: report--b57e186a-8861-5c8b-b639-3d8e44bbc389
Feed Name: ASEC
Threat Score
This AhnLab technical post explains how threat actors perform internal reconnaissance and credential theft in Active Directory domains—primarily using Mimikatz (executable, PowerShell, and DLL forms), ProcDump to dump LSASS, PowerView for enumeration, and various password-extraction utilities—and describes how AhnLab EDR detects these behaviors to enable incident identification and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
