Terminology Index
Glossary
1801 terms
Showing 449-480 of 1801 terms
Credential Access Hunts
Threat hunts focused on finding signs of credential theft that detections missed, searching telemetry for behaviors like memory access to credential stores, suspicious authentication, or tools associated with harvesting credentials.
Because credential access underpins so many intrusions and attackers work to evade detection, hunters proactively look for it: processes touching credential stores like LSASS, anomalous Kerberos activity, or use of known credential-dumping techniques. A credential-access hunt forms a hypothesis about how credentials might be stolen in the environment, operationalizes it into searches, and surfaces footholds that automated detection did not catch.
Introduced in: Threat Hunting Fundamentals
Examples
- Hunting for processes accessing LSASS memory to find credential dumping.
- Searching for anomalous Kerberos ticket requests indicating theft.
- Looking for traces of known credential-harvesting tools in telemetry.
No related terms linked yet.
