Documentação técnica dos caminhos onde senhas, credenciais e chaves SSH são armazenadas no Windows — referência para segurança defensiva, DFIR e hardening.
-
Updated
Jul 28, 2026
Documentação técnica dos caminhos onde senhas, credenciais e chaves SSH são armazenadas no Windows — referência para segurança defensiva, DFIR e hardening.
Unsupervised anomaly detector that flags early breach precursors (credential dumping, process injection) using Isolation Forest on EDR-style process features. Inspired by CrowdStrike-style EDR — includes confidence gating and human-readable explanations—deployed on Streamlit Cloud.
Wazuh SIEM lab detecting lsass credential access using Sysmon Event ID 10 and a custom rule targeting PROCESS_ALL_ACCESS (0x1FFFFF). Built in Proxmox homelab.
Red team credential access research — LSASS, DPAPI, browser credential stores, SAM. Lab/educational project scaffold.
Java program simulating ethical brute-force password attacks for cybersecurity practice.
# LSA Secrets Dumper - Windows Security Research Tool
Synthetic SOC / Blue Team credential access detection lab with MITRE ATT&CK mapping, SIEM detection logic, alert triage notes, false-positive handling, detection tuning, and dashboard reporting.
Simulated RDP brute force from Kali to Windows with Splunk detection, MITRE ATT&CK mapping (T1110), alerting, and defensive hardening.
Threat hunt for brute force login attempts against internet-exposed VMs using Microsoft Defender for Endpoint and KQL. Maps findings to MITRE ATT&CK T1110.
This repository contains a complete, analyst-grade walkthrough of the PoisonedCredentials lab form CyberDefenders, focusing on LLMNR/NBT-NS poisoning and network forensic analysis using Wireshark
Add a description, image, and links to the credential-access topic page so that developers can more easily learn about it.
To associate your repository with the credential-access topic, visit your repo's landing page and select "manage topics."