A deep dive into alternative Windows credential theft techniques beyond LSASS dumping, covering both attacker and defender perspectives. Topics include quick wins like stealer logs, plaintext password files, PowerShell ConsoleHost history, and GPP cPassword vulnerabilities, as well as advanced techniques: registering malicious Security Support Provider (SSP) DLLs, Password Filter DLLs, and Network Provider DLLs to intercept cleartext credentials at login. Real incident response case examples illustrate each technique. Detection guidance covers Sysmon Event IDs 11 and 13 for registry and file monitoring, and hardening recommendations include disabling custom SSPs, auditing AD attributes, and using tools like Snaffler and Velociraptor.

16m read timeFrom dfir.ch
Post cover image
Table of contents
1. Introduction2. Quick Wins3. Stealing Even More Cleartext PasswordsConclusion
192 Impressions