Cyberlium

Active › Module 7 › Lesson 3

BeginnerModule 7Lesson 3/5

LSA Credential Guard

LSA protection and Credential Guard literacy — reduce Pass-the-Hash and credential theft on $LAB_AD endpoints.

15 min+40 XP3 quiz
Module progress3 of 5

Visual · t25_lsa_cred_guard

LSA + Credential Guard = protect secrets on endpoint. Defender focus. Original Cyberlium.

Opening

Pass-the-Hash steals what LSA holds — Credential Guard and LSA protection keep Tier 0 off the workstation memory.

LSA (Local Security Authority) stores authentication secrets on Windows endpoints — Pass-the-Hash (Module 5 named) abuses NTLM hashes extracted from memory. Credential Guard uses virtualization-based security to isolate secrets; LSA protection (RunAsPPL) hardens lsass.exe against unsigned code injection. Additional literacy: Protected Users group, Restrict NTLM policy, WDigest disable, clear-text credential prevention. Defenders deploy on Tier 0/1 jump and PAW where hardware supports VBS. Cyberlium maps controls on YOUR $LAB_AD VM checklist — NOT Mimikatz cookbooks on stranger hosts, NOT disabling Defender on production to 'test PtH,' NOT extracting hashes from unauthorized systems. Lab: verify Credential Guard/LSA protection status on lab VM and document one PtH mitigation row.

1. LSA and PtH link

PtH reuses NTLM hash without plaintext — LSA is storage target on compromised host.

Tiering reduces which hashes exist on Tier 2 — defense in depth with Guard.

Command guide

Try these commands — LSA and PtH link

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

Credential Guard — https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard (LSA protection) Microsoft LSA protection — https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection (RunAsPPL) MITRE T1003 — https://attack.mitre.org/techniques/T1003/ (credential dumping — defender view)

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install curl
sudo apt install python3

macOS:

Command — copy this

brew install python3

Windows: Built-in (PowerShell: Invoke-WebRequest) Download https://python.org/downloads/

═══ LINUX / macOS ═══

Command — copy this

python3 - <<'PY'
print('LSA/Credential Guard: isolate secrets from Mimikatz-class dump — literacy')
print('BANNED in course: sekurlsa::logonpasswords, lsadump recipes')
print('Defender: enable Credential Guard on Tier 0 PAWs where supported')
PY

Command — copy this

curl -sS https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard | head -8

Primary tools to practice this lesson: curl, python3. Reference sites: Credential Guard (https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard); Microsoft LSA protection (https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection); MITRE T1003 (https://attack.mitre.org/techniques/T1003/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Credential Guard requirements

UEFI, Secure Boot, VBS, compatible CPU — document lab VM capability honestly N/A if nested VM lacks VBS.

RunAsPPL where Guard unavailable — still raises bar.

3. Refused

No hash dump exercises on unauthorized endpoints as course deliverable.

Literacy: control status + mitigation — not sekurlsa output from stranger PC.

4. What you ship: LSA Credential Guard card

LSA/PtH link + Guard/PPL checklist + lab VM status row + refuse hash dump line.

5. What you record before the next lesson

LSA Credential Guard card path.

6. Wrong vs right: stranger-domain attacks vs lab AD literacy

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    Run credential dump tools on roommate's laptop for lab evidence.

  • Right

    LSA Credential Guard card on $LAB_AD VM. Next: Defense Lab.

Mission: LSA Credential Guard card

1) Link LSA to PtH in one line. 2) List Guard requirements. 3) Check lab VM status. 4) Write NEVER unauthorized hash dump.

Stuck? Ask Cyberlium AI Mentor

Ask Mentor: “Nested lab VM — honest N/A for VBS?”

Knowledge Check

1

APPLY: Credential Guard isolates:

Multiple choice

Knowledge Check

2

APPLY: True or False: Hash dump on stranger PC is lab.

True or False

Knowledge Check

3

APPLY: PtH mitigations include:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)