Detecting T1003 Credential Dumping With Edr

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.

Njones17 Updated

File contents

Njones17/AI-agent-master-cyber-skills-list/tree/main/skills/detection/detecting-t1003-credential-dumping-with-edr commit 2d5af0c24f

Frequently asked questions

npx skillmds@latest add njones17/detecting-t1003-credential-dumping-with-edr