Detecting T1003 Credential Dumping With Edr

Detect OS credential dumping (MITRE T1003) targeting LSASS memory, the SAM database, NTDS.dit, and cached credentials by correlating EDR telemetry, Sysmon process-access events, and Windows security event logs. Use when hunting for Mimikatz-style credential theft, triaging an EDR alert on LSASS access, or scoping an incident after suspected credential dumping.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/detecting-t1003-credential-dumping-with-edr commit 59a87cfade

Frequently asked questions

npx skillmds@latest add gabrielmoreira/detecting-t1003-credential-dumping-with-edr