home.social

#mimikatz — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mimikatz, aggregated by home.social.

fetched live
  1. VMkatz: скрытая угроза для виртуальной инфраструктуры

    В 2026 году был опубликован инструмент VMkatz. По функционалу он напоминает широко известный инструмент Mimikatz, но, в отличие от него, целью VMkatz является извлечение учетных данных напрямую из файлов виртуальных машин (снимков памяти и виртуальных дисков) без необходимости входа внутрь гостевых Windows-систем. VMkatz может работать с файлами виртуальных машин разных платформ, включая VMware ESXi, Microsoft Hyper-V, VirtualBox и QEMU/KVM.

    habr.com/ru/companies/pt/artic

    #mimikatz #dfir #vmkatz #инструментарий #esxi #vmware_esxi #virtualbox

  2. VMkatz: скрытая угроза для виртуальной инфраструктуры

    В 2026 году был опубликован инструмент VMkatz. По функционалу он напоминает широко известный инструмент Mimikatz, но, в отличие от него, целью VMkatz является извлечение учетных данных напрямую из файлов виртуальных машин (снимков памяти и виртуальных дисков) без необходимости входа внутрь гостевых Windows-систем. VMkatz может работать с файлами виртуальных машин разных платформ, включая VMware ESXi, Microsoft Hyper-V, VirtualBox и QEMU/KVM.

    habr.com/ru/companies/pt/artic

    #mimikatz #dfir #vmkatz #инструментарий #esxi #vmware_esxi #virtualbox

  3. VMkatz: скрытая угроза для виртуальной инфраструктуры

    В 2026 году был опубликован инструмент VMkatz. По функционалу он напоминает широко известный инструмент Mimikatz, но, в отличие от него, целью VMkatz является извлечение учетных данных напрямую из файлов виртуальных машин (снимков памяти и виртуальных дисков) без необходимости входа внутрь гостевых Windows-систем. VMkatz может работать с файлами виртуальных машин разных платформ, включая VMware ESXi, Microsoft Hyper-V, VirtualBox и QEMU/KVM.

    habr.com/ru/companies/pt/artic

    #mimikatz #dfir #vmkatz #инструментарий #esxi #vmware_esxi #virtualbox

  4. Mimikatz token::elevate duplicates tokens to spawn a SYSTEM process from admin context, enabling LSASS credential dumping. token::revert restores original token. Works on Windows 7, Server 2008 R2+ x64. #mimikatz #token-manipulation #ValtersIT

    valtersit.com/vault/mimikatz-t

  5. The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz darkoperator.github.io/mimikat

  6. The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz darkoperator.github.io/mimikat

  7. The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz darkoperator.github.io/mimikat

  8. The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz darkoperator.github.io/mimikat

  9. The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz darkoperator.github.io/mimikat

  10. Lateral movement w Active Directory z wykorzystaniem WinRM

    Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....

    #Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm

    sekurak.pl/lateral-movement-w-

  11. Lateral movement w Active Directory z wykorzystaniem WinRM

    Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....

    #Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm

    sekurak.pl/lateral-movement-w-

  12. Lateral movement w Active Directory z wykorzystaniem WinRM

    Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....

    #Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm

    sekurak.pl/lateral-movement-w-

  13. Lateral movement w Active Directory z wykorzystaniem WinRM

    Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....

    #Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm

    sekurak.pl/lateral-movement-w-

  14. Lateral movement w Active Directory z wykorzystaniem WinRM

    Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....

    #Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm

    sekurak.pl/lateral-movement-w-

  15. ----------------

    🚨 Incident Response & Digital Forensics
    ===================

    Executive summary: The post documents Golden Ticket creation and highlights detection signals usable by Velociraptor. Golden Tickets are forged Kerberos TGTs signed with the krbtgt account NTLM hash, enabling domain-wide impersonation and long-term persistence.

    Technical details
    • The article lists the required artifacts for forging a Golden Ticket: domain name, Domain SID, target username and RID, and the krbtgt NTLM hash.
    • Demonstrated extraction steps include obtaining the Domain SID with PowerView and retrieving krbtgt credentials via DCSync (lsadump::dcsync /user:krbtgt).
    • Example artifacts shown in the post:
    S-1-5-21-3984707604-127893085-857657257
    d3c15f2d585d8e25ccd1834a037065cc
    Administrator (RID 500), groups 512,513,518,519
    Ticket lifetime example: 1/9/2026 to 1/7/2036.

    Analysis
    • Golden Tickets bypass normal Kerberos validation because the ticket is signed by the krbtgt key the domain trusts. This enables attackers to craft tickets for arbitrary accounts, including high-privilege ones, and request service tickets across the domain.
    • The post emphasizes that mimikatz can set very long lifetimes (the example shows a 10-year lifetime), which is a conspicuous artifact for detection.

    Detection (Velociraptor-focused signals reported in the article)
    • Monitor Kerberos TGT attributes for anomalous endtime values far in the future compared to normal ticket lifetimes.
    • Detect presence of PAC generation and PAC signature flags associated with tickets that do not correlate with legitimate authentication events.
    • Correlate indicators of krbtgt credential access (DCSync activity or NTDS access) and collection events such as PowerView enumeration.

    Limitations
    • The article provides demonstration artifacts and notes markers (long lifetimes, PAC signing) but does not include a formal rule set. Detection requires careful baseline of normal ticket lifetimes and correlation with directory access patterns.

    References / artifacts
    • Demonstrated artifacts in the post include the Domain SID S-1-5-21-3984707604-127893085-857657257 and krbtgt NTLM hash d3c15f2d585d8e25ccd1834a037065cc.

    🔹 kerberos #goldenticket #velociraptor #mimikatz #dfir

    🔗 Source: detect.fyi/detection-of-kerber

  16. 🎯 Threat Intelligence
    ===================

    Executive summary: SpecterOps published detailed research showing new methods to extract credentials from modern, fully patched Windows systems even when Credential Guard is enabled. The work focuses on how the Local Security Authority (LSA) and its interactions with Security Support Providers (SSPs) and the SSPI API can be leveraged to surface secrets that were presumed protected by Virtualization-Based Security (VBS).

    Technical details:
    • The research examines the lsass.exe process and the LSA architecture, emphasizing the role of lsasrv.dll in registering and managing SSPs such as msv1_0.dll (NTLM), kerberos.dll (Kerberos), schannel.dll (SSL/TLS), and the Negotiate broker.
    • The SSPI authentication flow is analyzed: acquiring credential handles (AcquireCredentialsHandle), initializing and accepting security contexts (InitializeSecurityContext / AcceptSecurityContext), and where secrets and handles are materialized in memory and IPC boundaries.
    • SpecterOps documents methods to interact with these flows to access credentials or artifacts that cross the VBS isolation boundary or are exposed via ancillary interfaces, producing a “new generation” of credential dumping techniques distinct from classical Mimikatz primitives.

    Analysis:
    • The findings suggest that Credential Guard substantially raises the bar but does not fully eliminate avenues for credential extraction when components that mediate authentication (SSPs/SSPI) are targeted. The work highlights subtle protocol and implementation interactions rather than a single exploitable CVE.
    • The research was validated on Windows 11 workstations and Windows Server 2025, indicating relevance to current enterprise deployments.

    Detection:
    • Focus detection on abnormal access patterns to LSA-related APIs, unexpected enumeration or manipulation of SSP contexts, and suspicious processes interacting with lsass.exe via supported IPC paths.
    • Correlate authentication anomalies (unexplained NTLM or Kerberos context creations) with process behavior to identify potential credential harvesting attempts.

    Mitigation / Defensive considerations:
    • Reinforce monitoring around LSA/SSP interactions, restrict unnecessary privileged access to authentication-related services, and apply principle-of-least-privilege to processes that can load or interact with SSPs.

    References:
    • SpecterOps research by Valdemar Carøe; prior public work by Oliver Lyak is noted as limited prior research into Credential Guard interactions.

    🔹 CredentialGuard #Mimikatz #VBS #LSA #Windows11

    🔗 Source: specterops.io/blog/2025/10/23/

  17. Защита процесса lsass от credential dumping

    Процесс lsass.exe (Local Security Authority Subsystem Service) — критически важный компонент ОС Windows. Он отвечает за аутентификацию пользователей и управление учетными данными. В его памяти хранятся хэши паролей NTLM, билеты Kerberos, данные сессий, а в некоторых конфигурациях — даже пароли в открытом виде, если используется устаревший протокол WDigest. Столь высокая концентрация секретов делает lsass.exe лакомой целью для злоумышленников, получивших доступ к системе. После Initial Access фазы атакующий будет стремиться повысить привилегии и двигаться дальше по сети. Дамп памяти lsass.exe — самый прямой и часто самый простой способ достичь этих целей, поскольку при отсутствии защиты атакующий очень легко извлекает оттуда данные для проведения атак Pass-the-hash и Pass-the-ticket. В то же время, для атаки на незащищенный lsass.exe, нужно сравнительно немного: права локального администратора и Mimikatz. Таким образом, защиту этого процесса, по моему мнению, нужно внести в базовый набор мероприятий для любой инфраструктуры с Windows-машинами. Существуют различные методы получения дампа lsass.exe. В материале мы рассмотрим как тривиальные, так и более изощренные, но не с позиции атакующего. Поскольку основная часть материала будет посвящена методам защиты lsass от извлечения данных, знакомство с различными способами атаки будет играть вспомогательную роль для лучшего понимания механики защитных мер.

    habr.com/ru/companies/first/ar

    #lsass #mimikatz #credentials

  18. Защита процесса lsass от credential dumping

    Процесс lsass.exe (Local Security Authority Subsystem Service) — критически важный компонент ОС Windows. Он отвечает за аутентификацию пользователей и управление учетными данными. В его памяти хранятся хэши паролей NTLM, билеты Kerberos, данные сессий, а в некоторых конфигурациях — даже пароли в открытом виде, если используется устаревший протокол WDigest. Столь высокая концентрация секретов делает lsass.exe лакомой целью для злоумышленников, получивших доступ к системе. После Initial Access фазы атакующий будет стремиться повысить привилегии и двигаться дальше по сети. Дамп памяти lsass.exe — самый прямой и часто самый простой способ достичь этих целей, поскольку при отсутствии защиты атакующий очень легко извлекает оттуда данные для проведения атак Pass-the-hash и Pass-the-ticket. В то же время, для атаки на незащищенный lsass.exe, нужно сравнительно немного: права локального администратора и Mimikatz. Таким образом, защиту этого процесса, по моему мнению, нужно внести в базовый набор мероприятий для любой инфраструктуры с Windows-машинами. Существуют различные методы получения дампа lsass.exe. В материале мы рассмотрим как тривиальные, так и более изощренные, но не с позиции атакующего. Поскольку основная часть материала будет посвящена методам защиты lsass от извлечения данных, знакомство с различными способами атаки будет играть вспомогательную роль для лучшего понимания механики защитных мер.

    habr.com/ru/companies/first/ar

    #lsass #mimikatz #credentials

  19. Защита процесса lsass от credential dumping

    Процесс lsass.exe (Local Security Authority Subsystem Service) — критически важный компонент ОС Windows. Он отвечает за аутентификацию пользователей и управление учетными данными. В его памяти хранятся хэши паролей NTLM, билеты Kerberos, данные сессий, а в некоторых конфигурациях — даже пароли в открытом виде, если используется устаревший протокол WDigest. Столь высокая концентрация секретов делает lsass.exe лакомой целью для злоумышленников, получивших доступ к системе. После Initial Access фазы атакующий будет стремиться повысить привилегии и двигаться дальше по сети. Дамп памяти lsass.exe — самый прямой и часто самый простой способ достичь этих целей, поскольку при отсутствии защиты атакующий очень легко извлекает оттуда данные для проведения атак Pass-the-hash и Pass-the-ticket. В то же время, для атаки на незащищенный lsass.exe, нужно сравнительно немного: права локального администратора и Mimikatz. Таким образом, защиту этого процесса, по моему мнению, нужно внести в базовый набор мероприятий для любой инфраструктуры с Windows-машинами. Существуют различные методы получения дампа lsass.exe. В материале мы рассмотрим как тривиальные, так и более изощренные, но не с позиции атакующего. Поскольку основная часть материала будет посвящена методам защиты lsass от извлечения данных, знакомство с различными способами атаки будет играть вспомогательную роль для лучшего понимания механики защитных мер.

    habr.com/ru/companies/first/ar

    #lsass #mimikatz #credentials

  20. Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?

    Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.

    If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.

  21. Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?

    Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.

    If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.

  22. Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?

    Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.

    If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.

  23. Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?

    Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.

    If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.

  24. Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?

    Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.

    If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.

  25. 😈 Атаки на Active Directory: от 0 до 0,9.

    #pentest #ActiveDirectory #mimikatz #MSSQL #RDP #rpc #smb #SSH

    Цель статьи — рассмотреть Active Directory с точки зрения злоумышленника. Чтобы понять, как атаковать Active Directory, необходимо знать не только перечень инструментов, но и то, как они работают, какие протоколы/механизмы они используют и почему эти механизмы/протоколы существуют.

    • Оригинал: zer1t0.gitlab.io/posts/attacki

    • Перевод RU:

    1. defcon.ru/penetration-testing/
    2. defcon.ru/penetration-testing/
    3. defcon.ru/penetration-testing/
    4. defcon.ru/penetration-testing/
    5. defcon.ru/penetration-testing/
    6. defcon.ru/penetration-testing/
    7. defcon.ru/penetration-testing/

  26. 😈 Атаки на Active Directory: от 0 до 0,9.

    #pentest #ActiveDirectory #mimikatz #MSSQL #RDP #rpc #smb #SSH

    Цель статьи — рассмотреть Active Directory с точки зрения злоумышленника. Чтобы понять, как атаковать Active Directory, необходимо знать не только перечень инструментов, но и то, как они работают, какие протоколы/механизмы они используют и почему эти механизмы/протоколы существуют.

    • Оригинал: zer1t0.gitlab.io/posts/attacki

    • Перевод RU:

    1. defcon.ru/penetration-testing/
    2. defcon.ru/penetration-testing/
    3. defcon.ru/penetration-testing/
    4. defcon.ru/penetration-testing/
    5. defcon.ru/penetration-testing/
    6. defcon.ru/penetration-testing/
    7. defcon.ru/penetration-testing/

  27. 😈 Атаки на Active Directory: от 0 до 0,9.

    #pentest #ActiveDirectory #mimikatz #MSSQL #RDP #rpc #smb #SSH

    Цель статьи — рассмотреть Active Directory с точки зрения злоумышленника. Чтобы понять, как атаковать Active Directory, необходимо знать не только перечень инструментов, но и то, как они работают, какие протоколы/механизмы они используют и почему эти механизмы/протоколы существуют.

    • Оригинал: zer1t0.gitlab.io/posts/attacki

    • Перевод RU:

    1. defcon.ru/penetration-testing/
    2. defcon.ru/penetration-testing/
    3. defcon.ru/penetration-testing/
    4. defcon.ru/penetration-testing/
    5. defcon.ru/penetration-testing/
    6. defcon.ru/penetration-testing/
    7. defcon.ru/penetration-testing/

  28. 😈 Атаки на Active Directory: от 0 до 0,9.

    #pentest #ActiveDirectory #mimikatz #MSSQL #RDP #rpc #smb #SSH

    Цель статьи — рассмотреть Active Directory с точки зрения злоумышленника. Чтобы понять, как атаковать Active Directory, необходимо знать не только перечень инструментов, но и то, как они работают, какие протоколы/механизмы они используют и почему эти механизмы/протоколы существуют.

    • Оригинал: zer1t0.gitlab.io/posts/attacki

    • Перевод RU:

    1. defcon.ru/penetration-testing/
    2. defcon.ru/penetration-testing/
    3. defcon.ru/penetration-testing/
    4. defcon.ru/penetration-testing/
    5. defcon.ru/penetration-testing/
    6. defcon.ru/penetration-testing/
    7. defcon.ru/penetration-testing/

  29. Охота за кредами

    Существуют различные способы аутентификации в системах Windows, каждый из этих способов сохраняет или кэширует переданные учетные данные. В этом модуле мы рассмотрим основные типы аутентификации и места кэширования переданных данных, а также разберем, как можно получить к ним доступ.

    habr.com/ru/articles/806831/

    #CredentialAccess #SAM #LSA #lsass #NTDSDIT #mimikatz #windows #active_directory #redteam #pentest

  30. Охота за кредами

    Существуют различные способы аутентификации в системах Windows, каждый из этих способов сохраняет или кэширует переданные учетные данные. В этом модуле мы рассмотрим основные типы аутентификации и места кэширования переданных данных, а также разберем, как можно получить к ним доступ.

    habr.com/ru/articles/806831/

    #CredentialAccess #SAM #LSA #lsass #NTDSDIT #mimikatz #windows #active_directory #redteam #pentest

  31. Эксперименты с Golden Ticket

    Пожалуй, одной из самых опасных и крайне нежелательных сущностей, которые могут завестись в скомпрометированной Windows-инфраструктуре, является Golden Ticket. Это абсолютно легитимный Kerberos-билет, содержащий специально созданные данные, позволяющие злоумышленнику обойти нормальные механизмы проверки и получить высокие привилегии в сети. С помощью золотого билета злоумышленник может получить доступ к любому ресурсу в Active Directory, притворяясь валидным пользователем, без фактической аутентификации. Про Golden Ticket написано уже очень много статей, и аналитики знают, что такую атаку очень сложно обнаружить (большой труд в этом направлении проделали коллеги из R-Vision, рекомендуем к прочтению статью о Golden Ticket ). Не так давно Microsoft выпустила поэтапные обновления безопасности, которые меняют правила использования Golden Ticket. В этой статье мы постараемся разобраться, как обстоят дела с этой атакой сейчас и как Microsoft упростила ее детектирование своими обновлениями. Мы возьмем два инструмента (Mimikatz и Rubeus), сделаем с помощью них Golden Ticket с разными параметрами, а потом попробуем ими воспользоваться и посмотрим, какие сгенерируются события и как отследить их в SOC.

    habr.com/ru/companies/jetinfos

    #kerberos #атака #microsoft #детектирование #mimikatz #rubeus #soc #обновление_безопасности #system #события_журнала

  32. Эксперименты с Golden Ticket

    Пожалуй, одной из самых опасных и крайне нежелательных сущностей, которые могут завестись в скомпрометированной Windows-инфраструктуре, является Golden Ticket. Это абсолютно легитимный Kerberos-билет, содержащий специально созданные данные, позволяющие злоумышленнику обойти нормальные механизмы проверки и получить высокие привилегии в сети. С помощью золотого билета злоумышленник может получить доступ к любому ресурсу в Active Directory, притворяясь валидным пользователем, без фактической аутентификации. Про Golden Ticket написано уже очень много статей, и аналитики знают, что такую атаку очень сложно обнаружить (большой труд в этом направлении проделали коллеги из R-Vision, рекомендуем к прочтению статью о Golden Ticket ). Не так давно Microsoft выпустила поэтапные обновления безопасности, которые меняют правила использования Golden Ticket. В этой статье мы постараемся разобраться, как обстоят дела с этой атакой сейчас и как Microsoft упростила ее детектирование своими обновлениями. Мы возьмем два инструмента (Mimikatz и Rubeus), сделаем с помощью них Golden Ticket с разными параметрами, а потом попробуем ими воспользоваться и посмотрим, какие сгенерируются события и как отследить их в SOC.

    habr.com/ru/companies/jetinfos

    #kerberos #атака #microsoft #детектирование #mimikatz #rubeus #soc #обновление_безопасности #system #события_журнала

  33. TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡

    Except attacks to steal credentials are prevented with Credential Guard.

    #Windows #mimikatz #sysadmin

  34. TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡

    Except attacks to steal credentials are prevented with Credential Guard.

  35. TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡

    Except attacks to steal credentials are prevented with Credential Guard.

    #Windows #mimikatz #sysadmin

  36. TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡

    Except attacks to steal credentials are prevented with Credential Guard.

    #Windows #mimikatz #sysadmin

  37. TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡

    Except attacks to steal credentials are prevented with Credential Guard.

    #Windows #mimikatz #sysadmin

  38. Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday

  39. Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday

  40. Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday

  41. Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday