logo

Credential Theft: Expanding Your Reach

ID: f108610b-007d-52b2-93b8-bcd72978c450

STIX ID: report--f108610b-007d-52b2-93b8-bcd72978c450

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2025-04-08

Date Updated: 2026-04-28

...
...

This Huntress report outlines credential theft tactics across the attack lifecycle: common initial access methods (phishing, malicious downloads, brute force, vulnerable exposed services), and post-exploitation techniques for harvesting credentials (infostealers, password recovery tools, Mimikatz, Registry hive and LSASS memory dumps, enabling WDigest, and NTDS.dit extraction). The document includes observed command examples, abuse of LOLBins and Volume Shadow Copies, and recommended controls such as security awareness, asset inventory, attack surface reduction, and endpoint monitoring to detect and mitigate these activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.