Agent Skills: detecting-t1003-credential-dumping-with-edr

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.

UncategorizedID: plurigrid/asi/detecting-t1003-credential-dumping-with-edr

Install this agent skill to your local

pnpm dlx add-skill https://github.com/plurigrid/asi/detecting-t1003-credential-dumping-with-edr

Skill Files

Browse the full folder contents for detecting-t1003-credential-dumping-with-edr.

Download Skill

Loading file tree…

Select a file to preview its contents.