logo

Account Credentials Theft in Domain Environments Detected by EDR

ID: b57e186a-8861-5c8b-b639-3d8e44bbc389

STIX ID: report--b57e186a-8861-5c8b-b639-3d8e44bbc389

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-01-09

Date Updated: 2026-04-26

Author: ASEC

...
...

This AhnLab technical post explains how threat actors perform internal reconnaissance and credential theft in Active Directory domains—primarily using Mimikatz (executable, PowerShell, and DLL forms), ProcDump to dump LSASS, PowerView for enumeration, and various password-extraction utilities—and describes how AhnLab EDR detects these behaviors to enable incident identification and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.