Credential Dumping: Windows Authentication and Credential Management
ID: c74fc921-7f24-55dd-b86b-d1a0f16225de
STIX ID: report--c74fc921-7f24-55dd-b86b-d1a0f16225de
Feed Name: ReliaQuest Blog
This blog post provides an overview of Windows credential management and how attackers steal credentials by dumping LSASS memory and extracting LSA secrets. It explains LSASS behavior, common tools and methods used for credential theft (notably Mimikatz, Procdump, and Task Manager dumps), the risks posed by cached credentials and LSA secrets, and points to mitigations and detection options such as using ReliaQuest GreyMatter for monitoring and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
