A comprehensive map of NT hash, Kerberos ticket, and plaintext password theft via memory dumping of Windows authentication backbone LSASS (lsass.exe): Mimikatz/sekurlsa, comsvcs LOLBin, ProcDump, and nanodump attack methods; Sysmon EID 10 GrantedAccess masks + Sigma-based technical detection; Credential Guard, RunAsPPL, WDigest disable, and ASR rule hardening controls.
Technique Library
MITRE ATT&CK-based attack techniques — Exploit · Prevention · Detection
7 techniques · Credential Access