Detecting Credential Dumping Techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

26zl a5e2567 4 files · 24.6 KB Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/detecting-credential-dumping-techniques commit a5e25678bc

Frequently asked questions

npx skillmds@latest add 26zl/detecting-credential-dumping-techniques