Documentação técnica dos caminhos onde senhas, credenciais e chaves SSH são armazenadas no Windows — referência para segurança defensiva, DFIR e hardening.
-
Updated
Jul 31, 2026
Documentação técnica dos caminhos onde senhas, credenciais e chaves SSH são armazenadas no Windows — referência para segurança defensiva, DFIR e hardening.
DPAPI Is Not a Boundary — A Full Infostealer Kill Chain Operators Can Replicate. Red Team Village workshop lab guide by Filipi Pires.
Unsupervised anomaly detector that flags early breach precursors (credential dumping, process injection) using Isolation Forest on EDR-style process features. Inspired by CrowdStrike-style EDR — includes confidence gating and human-readable explanations—deployed on Streamlit Cloud.
# LSA Secrets Dumper - Windows Security Research Tool
Wazuh SIEM lab detecting lsass credential access using Sysmon Event ID 10 and a custom rule targeting PROCESS_ALL_ACCESS (0x1FFFFF). Built in Proxmox homelab.
Red team credential access research — LSASS, DPAPI, browser credential stores, SAM. Lab/educational project scaffold.
Credential-access risk assessment for GCP
Systematic detection engineering on MITRE ATT&CK — the Credential Access tactic decomposed into a full detection suite plus a correlation layer, with range-proving builds in Execution and C2. Microsoft Sentinel · KQL · Defender for Endpoint.
Credential-access risk assessment for AWS
Modules to backdoor and capture clear text credentials in PAM.
Java program simulating ethical brute-force password attacks for cybersecurity practice.
Using LLMNR\NBT-NS poisoning to retrieve Username + Password NTLMv2 hash from AD DS
Synthetic SOC / Blue Team credential access detection lab with MITRE ATT&CK mapping, SIEM detection logic, alert triage notes, false-positive handling, detection tuning, and dashboard reporting.
Credential-access risk assessment for Azure
Simulated RDP brute force from Kali to Windows with Splunk detection, MITRE ATT&CK mapping (T1110), alerting, and defensive hardening.
Threat hunt for brute force login attempts against internet-exposed VMs using Microsoft Defender for Endpoint and KQL. Maps findings to MITRE ATT&CK T1110.
This repository contains a complete, analyst-grade walkthrough of the PoisonedCredentials lab form CyberDefenders, focusing on LLMNR/NBT-NS poisoning and network forensic analysis using Wireshark
To associate your repository with the credential-access topic, visit your repo's landing page and select "manage topics."