Hunting Windows Credential Material Exposure

Hunt exposure of Windows credential material, where secrets that authenticate a user or machine, cached logon verifiers, stored service and task passwords, protected-store secrets, saved connection credentials, and credentials left in memory of a privileged process, are readable by a principal that should not reach them because of a weak permission, an over-privileged token, or storage that does not bind the secret to the intended account. Use when reviewing where Windows keeps authentication secrets and which principals can read each store. Covers cached verifiers, service and scheduled-task secrets, protected-store material, saved credentials, and process memory. The readable credential store or process is the source, the read that recovers usable secret material is the sink, and obtaining a credential the reader was not entitled to is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-windows-credential-material-exposure commit 2748087a04

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-windows-credential-material-exposure