open-menu
closeme
Kerberoasting Activity - Initial query
calendar
Aug 10, 2024
·
attack.credential_access
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
LAPS Credential Dumping Spoofing and Domain Controller Impersonation
calendar
Aug 10, 2024
·
attack.credential_access
attack.T1003
·
Share on:
twitter
facebook
linkedin
copy
Using Lazagne to dump credentials
calendar
Aug 10, 2024
·
attack.credential_access
attack.t1555
·
Share on:
twitter
facebook
linkedin
copy
Kerberos .kirbi Ticket Files
calendar
Mar 26, 2024
·
attack.s0002
attack.credential_access
attack.t1558
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
Mimikatz Module Names
calendar
Mar 26, 2024
·
attack.credential_access
attack.t1003
attack.s0002
·
Share on:
twitter
facebook
linkedin
copy
SecretsDump File Modification
calendar
Mar 26, 2024
·
attack.credential_access
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
Secretsdump.py Execution
calendar
Mar 26, 2024
·
attack.s0357
attack.credential_access
attack.t1003
attack.t1003.003
attack.t1003.006
·
Share on:
twitter
facebook
linkedin
copy
Suspicious Export Functionalities - Rundll32
calendar
Mar 26, 2024
·
attack.defense_evasion
attack.t1218
attack.t1218.011
attack.credential_access
attack.t1003
·
Share on:
twitter
facebook
linkedin
copy
Lazagne dumping credentials
calendar
Feb 23, 2024
·
attack.credential_access
attack.t1555
·
Share on:
twitter
facebook
linkedin
copy
Adding, Listing and Removing Credentials via Cmdkey CommandLine Ultility
calendar
Oct 30, 2023
·
attack.credential_access
attack.t1003.005
·
Share on:
twitter
facebook
linkedin
copy
Possible Impacket Secretsdump.py Activity
calendar
Sep 1, 2023
·
attack.s0357
attack.credential_access
attack.t1003
attack.t1003.003
attack.t1003.006
·
Share on:
twitter
facebook
linkedin
copy
Abnormal LSASS Child and Parent Process Relationships (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Abnormal LSASS Process Access and Injection (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
LSASS Running Under Non-Privileged User Context (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Rundll32 Dumping Credentials with MiniDump Function (RedCanary Threat Detection Report)
calendar
May 10, 2023
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Failed Logins with Different Accounts from Single Source - Linux
calendar
Apr 21, 2023
·
attack.credential_access
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Sign-in Failure Bad Password Threshold
calendar
Apr 21, 2023
·
attack.credential_access
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Stored Credentials in Fake Files
calendar
Apr 21, 2023
·
attack.credential_access
attack.t1555
·
Share on:
twitter
facebook
linkedin
copy
Possible Impacket GetUserSPNs Activity
calendar
Apr 16, 2023
·
attack.s0357
attack.credential_access
attack.t1558
attack.t1558.003
·
Share on:
twitter
facebook
linkedin
copy
External Remote Service Logon from Public IP
calendar
Jan 23, 2023
·
attack.initial_access
attack.credential_access
attack.t1133
attack.t1078
attack.t1110
·
Share on:
twitter
facebook
linkedin
copy
Mimikatz Command Line With Ticket Export
calendar
Jan 8, 2023
·
attack.credential_access
attack.t1003
attack.t1003.001
attack.t1003.002
attack.t1003.004
attack.t1003.005
attack.t1003.006
·
Share on:
twitter
facebook
linkedin
copy
NTDSutil Pulling of NTDS.dit File
calendar
Nov 29, 2022
·
attack.credential_access
attack.t1003
attack.t1003.003
·
Share on:
twitter
facebook
linkedin
copy
Abnormal LSASS Child and Parent Process Relationships
calendar
Nov 9, 2022
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
Abnormal LSASS Process Access and Injection
calendar
Nov 9, 2022
·
attack.credential_access
attack.t1003.001
·
Share on:
twitter
facebook
linkedin
copy
to-top