credential access

About this tag
Credential access is a critical tactic in the MITRE ATT&CK framework, frequently employed by ransomware groups like BlackMatter and Conti, as well as state-sponsored actors such as APT40. Discussions on WindowsForum highlight how adversaries use credential theft to gain initial access, move laterally, and escalate privileges within Windows environments. Topics include securing credentials against brute-force attacks, phishing, and credential dumping, with emphasis on implementing multi-factor authentication, least privilege policies, and monitoring for anomalous logins. The tag covers defensive strategies to protect Microsoft Active Directory, Azure AD, and local Windows accounts from compromise, drawing from real-world threat intelligence and cybersecurity advisories.
  1. Edchart & Credly Partnership Boosts Microsoft Cognitive Toolkit Certifications

    Edchart's recent partnership with Credly to offer Microsoft Cognitive Toolkit Machine Learning certifications marks a significant advancement in the validation and recognition of digital skills globally. This collaboration aims to provide professionals with verifiable credentials that attest to...
  2. AA21-291A: BlackMatter Ransomware

    Original release date: October 18, 2021 Summary Actions You Can Take Now to Protect Against BlackMatter Ransomware • Implement and enforce backup and restoration policies and procedures. • Use Link Removed. • Use Link Removed. • Implement network segmentation and traversal monitoring. Note...
  3. VIDEO AA21-265A: Conti Ransomware

    Original release date: September 22, 2021 Summary Immediate Actions You Can Take Now to Protect Against Conti Ransomware • Use Link Removed. • Segment and segregate networks and functions. • Update your operating system and software. Note: This Alert uses the MITRE Adversarial Tactics...
  4. AA21-200B: Chinese State-Sponsored Cyber Operations: Observed TTPs

    Original release date: July 19, 2021 Summary This advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework, Version 9, and MITRE D3FEND™ framework, version 0.9.2-BETA-3. See the ATT&CK for Enterprise for all referenced threat actor tactics and techniques...
  5. AA21-200A: Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department

    Original release date: July 19, 2021 Summary This Joint Cybersecurity Advisory was written by the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) to provide information on a Chinese Advanced Persistent Threat (APT) group known in open-source...