Skip to content

Opening book details…

About this document

OS Credential Dumping by mewigof200 is a document available to read on EtoBox.

The document outlines various techniques and detection methods for LSASS memory credential dumping, emphasizing the use of legitimate Windows binaries like rundll32.exe and comsvcs.dll by attackers to evade detection. It details the processes involved in credential theft, including transferring stolen data via network shares and the significance of monitoring specific Windows Event IDs for suspicious activities. Additionally, it highlights high-confidence indicators of compromise, such as unauthorized acces

Author
mewigof200
Language
EN