Documentação técnica dos caminhos onde senhas, credenciais e chaves SSH são armazenadas no Windows — referência para segurança defensiva, DFIR e hardening.
-
Updated
Jul 31, 2026
Documentação técnica dos caminhos onde senhas, credenciais e chaves SSH são armazenadas no Windows — referência para segurança defensiva, DFIR e hardening.
DPAPI Is Not a Boundary — A Full Infostealer Kill Chain Operators Can Replicate. Red Team Village workshop lab guide by Filipi Pires.
Unsupervised anomaly detector that flags early breach precursors (credential dumping, process injection) using Isolation Forest on EDR-style process features. Inspired by CrowdStrike-style EDR — includes confidence gating and human-readable explanations—deployed on Streamlit Cloud.
Wazuh SIEM lab detecting lsass credential access using Sysmon Event ID 10 and a custom rule targeting PROCESS_ALL_ACCESS (0x1FFFFF). Built in Proxmox homelab.
Red team credential access research — LSASS, DPAPI, browser credential stores, SAM. Lab/educational project scaffold.
Java program simulating ethical brute-force password attacks for cybersecurity practice.
Modules to backdoor and capture clear text credentials in PAM.
# LSA Secrets Dumper - Windows Security Research Tool
Simulated RDP brute force from Kali to Windows with Splunk detection, MITRE ATT&CK mapping (T1110), alerting, and defensive hardening.
Synthetic SOC / Blue Team credential access detection lab with MITRE ATT&CK mapping, SIEM detection logic, alert triage notes, false-positive handling, detection tuning, and dashboard reporting.
Threat hunt for brute force login attempts against internet-exposed VMs using Microsoft Defender for Endpoint and KQL. Maps findings to MITRE ATT&CK T1110.
This repository contains a complete, analyst-grade walkthrough of the PoisonedCredentials lab form CyberDefenders, focusing on LLMNR/NBT-NS poisoning and network forensic analysis using Wireshark
Add a description, image, and links to the credential-access topic page so that developers can more easily learn about it.
To associate your repository with the credential-access topic, visit your repo's landing page and select "manage topics."