Detecting Credential Dumping Techniques

Detect LSASS credential dumping, SAM database extraction, and NTDS.dit theft using Sysmon Event ID 10, Windows Security logs, and SIEM correlation rules

xalgord 7bcb49f 3.5 KB Updated

File contents

xalgord/xalgorix/tree/main/internal/tools/skills/data/threat-detection/detecting-credential-dumping-techniques commit 7bcb49ff86

Frequently asked questions

npx skillmds@latest add xalgord/detecting-credential-dumping-techniques