BigHugger
sk Skill · mukul975

detecting-credential-dumping-techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft (e.g. via Mimikatz) using Sysmon Event ID 10 process-access logging, Windows Security logs, and SIEM correlation rules. Use when hunting for credential-theft activity on Windows/Active Directory hosts or triaging EDR alerts on LSASS access.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
defense-evasionwindows-securityactive-directorysysmonmimikatzlsassPythoncredential-dumping
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python