Detecting Credential Dumping Techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

theheavenlyd3mon f7add20 5 files · 26.9 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/detecting-credential-dumping-techniques commit f7add2087b

Frequently asked questions

npx skillmds add theheavenlyd3mon/detecting-credential-dumping-techniques