Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Credential Guard

From Wikipedia, the free encyclopedia
Computer operating system component

Credential Guard is a virtualization-based isolation technology forLSASS which prevents attackers from stealing credentials that could be used forpass the hash attacks.[1][2][3][4] Credential Guard was introduced withMicrosoft'sWindows 10 operating system.[1] As of Windows 11 version 22H2, Credential Guard is only available in the Enterprise edition of the operating system.[5]

Summary

[edit]

After compromising a system, attackers often attempt to extract any stored credentials for further lateral movement through the network. A prime target is theLSASS process, which stores NTLM andKerberos credentials. Credential Guard prevents attackers from dumping credentials stored in LSASS by running LSASS in a virtualized container that even a user with SYSTEM privileges cannot access.[6] The system then creates a proxy process called LSAIso (LSA Isolated) for communication with the virtualized LSASS process.[7][3][8]

Bypass techniques

[edit]

There are several generic techniques for stealing credentials on systems with Credential Guard:

  • A keylogger running on the system will capture any typed passwords.[9][3]
  • A user with administrator privileges can install a new Security Support Provider (SSP). The new SSP will not be able to access stored password hashes, but will be able to capture all passwords after the SSP is installed.[9][10]
  • Extract stored credentials from another source, as is performed in the "Internal Monologue" attack (which uses SSPI to retrieve crackable NetNTLMv1 hashes).[11]

References

[edit]
  1. ^ab"Protect derived domain credentials with Windows Defender Credential Guard".Windows IT Pro Center. Retrieved14 September 2018.
  2. ^"Analysis of the attack surface of windows 10 virtualization-based security"(PDF).blackhat.com. Retrieved13 November 2018.
  3. ^abcYosifovich, Pavel;Russinovich, Mark (5 May 2017).Windows Internals, Part 1: System architecture, processes, threads, memory management, and more, Seventh Edition. Microsoft Press.ISBN 978-0-13-398647-1.
  4. ^"Credential Guard Cheat Sheet".insights.adaptiva.com. Retrieved13 November 2018.
  5. ^"Credential Guard overview | Microsoft Learn".Microsoft Learn. 2025-02-25. Retrieved2026-02-03.
  6. ^"Deep Dive into Credential Guard, Credential Theft & Lateral Traversal".Microsoft Virtual Academy. Retrieved17 September 2018.
  7. ^"Windows 10 Device Guard and Credential Guard Demystified".Microsoft TechNet, Ash's blog. 2 March 2016. Retrieved17 September 2018.
  8. ^"Technique: Credential Dumping".attack.mitre.org. Retrieved8 July 2019.
  9. ^ab"Windows Credential Guard & Mimikatz".nviso labs. 2018-01-09. Retrieved14 September 2018.
  10. ^"Third party Security Support Providers with Credential Guard".Windows Dev Center. Retrieved14 September 2018.
  11. ^"Retrieving NTLM Hashes without touching LSASS: the "Internal Monologue" Attack".andreafortuna.org. Archived fromthe original on 26 May 2018. Retrieved5 November 2018.
Management
tools
Apps
Shell
Services
File systems
Server
Architecture
Security
Compatibility
API
Games
Discontinued
Games
Apps
Others
Spun off to
Microsoft Store
Retrieved from "https://en.wikipedia.org/w/index.php?title=Credential_Guard&oldid=1336331915"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp