LSASS Credential Dumpin
This playbook is focused on detecting Credential Dumping attack as researched by Accenture Security analysts and engineers.
- Pack
- LSASSCredentialDumping
- Tasks
- 25
Commands used
- cb-eedr-device-quarantine
- extractIndicators
- isWhitelisted
- servicenow-create-ticket
- servicenow-update-ticket
- splunk-search
- tanium-tr-delete-file-from-endpoint
- tanium-tr-get-file-info