Credential theft huntingΒΆ
Runbooks for hunting credential dumping activity and authentication abuse patterns in Windows Security event logs. The LSASS hunt covers process memory access and offline extraction techniques; the spray hunt covers source-based failure clustering, lockout bursts, and failure-to-success sequences.