Detecting T1003 Credential Dumping With Edr

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.

theheavenlyd3mon 8a67f86 8 files · 36.6 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-soc/skills/Anthropic-Cybersecurity-Skills/skills/detecting-t1003-credential-dumping-with-edr commit 8a67f86a4d

Frequently asked questions

npx skillmds add theheavenlyd3mon/detecting-t1003-credential-dumping-with-edr