Block Cred Dumps using Attack Surface Reduction Rules in Windows

แชร์
ฝัง
  • เผยแพร่เมื่อ 22 ก.ค. 2024
  • Credential dumping is a common technique among cyber criminals. This literally allows access to the keys that control the kingdom leading to complete dominance. So how do you block it? I'm going to show you an easy way using Attack Surface Reduction rules in Windows...
    Demystifying Attack Surface Reduction Rules: techcommunity.microsoft.com/t...
    Deployment Documentation: docs.microsoft.com/en-us/wind...
    Table of Contents:
    00:00:00 Intro
    00:00:35 Disclaimer
    00:00:54 Demo w/o ASR
    00:04:12 Demo w/ASR
    00:05:33 Final Thoughts
    Note: The views and expressions on my videos do not represent those of my employer and are strictly my own.
    All content provided on this channel is for informational purposes only. The owner of this channel makes no representations as to the accuracy or completeness of any information on this site or found by following any link on this channel.
    The owner of this channel will not be liable for any errors or omissions in this information nor for the availability of this information. The owner will not be liable for any losses, injuries, or damages from the display or use of this information.
    These terms and conditions is subject to change at anytime with or without notice.
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 7

  • @mukte81
    @mukte81 3 ปีที่แล้ว

    Wonderful

  • @myusrn
    @myusrn 3 ปีที่แล้ว +1

    Why is this asr blocking lsass.exe process credential dumping not enabled by default in windows 10 installs, e.g. we tested with windows 10 21h1 rtm and 21h2 preview pro installs and you can dump lsass.exe by default. Seems wrong that you have to be an enterprise user with intune, sccm or gpo policy enabling credential guard rule in order to be protected.

  • @leifdavisson6409
    @leifdavisson6409 3 ปีที่แล้ว

    Is there log entries for IOCs on this process? Before or After implementing Attack Surface Reduction? It would be nice to tie this in with a SIEM.

  • @AhmetDoruk
    @AhmetDoruk 3 ปีที่แล้ว

    this is amazing

    • @AhmetDoruk
      @AhmetDoruk 3 ปีที่แล้ว

      for local admins

    • @MattSoseman
      @MattSoseman  3 ปีที่แล้ว

      Local admins? What do you mean?

    • @AhmetDoruk
      @AhmetDoruk 3 ปีที่แล้ว

      ​@@MattSoseman standart users cant create dump files but administrator users can do. However very efficient method for ASR