Skip to main content

detecting-t1003-credential-dumping-with-edr

Detect OS credential dumping techniques targeting LSASS memory, SAM database, NTDS.dit, and cached credentials using EDR telemetry, Sysmon process access monitoring, and Windows security event correlation.

Jump to install

Source facts

Repository
xalgord/xalgorix
Last source activity
June 6, 2026 at 16:41
Detected SKILL.md language
English
Stars
813
Forks
146

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.