High severityHARDEC6 steps · 6 phases
Compromised Credentials & Account Takeover
Response for compromised user/service/privileged account takeover.
Information note
Informational note: In compromised credential response, a password reset alone is insufficient; NTLM hashes, Kerberos tickets, and delegation tokens obtained from LSASS memory can be abused independently. Close all credential leak vectors under MITRE T1003: enable Credential Guard, enforce the Protected Users group, and plan regular password rotation and migration to MSA/gMSA for service accounts.
1
Preparation
1 steps- Identity telemetry
IdP/AD session logs, impossible travel detection, privileged account inventory.
2
Identification
1 steps- Identify the account and access
Abnormal sign-in, MFA fatigue, new device/OAuth grant, token reuse.
3
Containment
1 steps- Revoke access
Reset password, revoke all session/refresh tokens, re-enroll MFA, remove abnormal MFA methods.
4
Eradication
1 steps- Remove persistence