BigHugger
sk Skill · mukul975

detecting-t1003-credential-dumping-with-edr

Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access events, and Windows security event logs. Use when hunting for Mimikatz-style credential theft, triaging an EDR alert on LSASS access, or scoping an incident after suspected credential dumping.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
kqlsam-databasemimikatzntdsedrlsassPythonmitre-t1003credential-dumpingyamlsplthreat-hunting
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python