detecting-t1003-credential-dumping-with-edr
Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.
Source facts
- Repository
- AgentFlocks/flocks
- Last source activity
- May 5, 2026 at 05:45
- Detected SKILL.md language
- English
- Stars
- 445
- Forks
- 83
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.