暴力破解:密码破解
原名:Brute Force: Password Cracking
通过 Sysmon 事件 ID 10、Windows 安全日志及 SIEM 关联规则,检测 LSASS 凭据转储、SAM 数据库提取及 NTDS.dit 窃取行为,适用于 Windows/AD 主机上的凭据窃取狩猎或 EDR 告警排查。
- 分类
- 开发提效
- 版本
- v1.1
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-07
- TRACE 评分
- 0 / 5
内容概览
Credential dumping (MITRE ATT&CK T1003) is a post-exploitation technique where adversaries extract authentication credentials from OS memory, registry hives, or domain controller databases. This skill covers detection of LSASS memory access via Sysmon Event ID 10 (ProcessAccess), SAM registry hive export via reg.exe, NTDS.dit extraction via ntdsutil/vssadmin, and comsvcs.dll MiniDump abuse. Detection rules analyze GrantedAccess bitmasks, suspicious calling processes, and known tool signatures. - When investigating security incidents that require detecting credential dumping techniques - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Sysmon v14+ deployed with ProcessAccess logging (Event ID 10) for lsass.exe - Windows…