redcanaryco / atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.
MIT License
9.76k stars 2.8k forks source link

Update T1003.yaml #2834

Closed skandler closed 4 months ago

skandler commented 4 months ago

Details: added dumping kerberos tickets from winlogon.exe with dumper.ps1 https://github.com/MzHmO/PowershellKerberos

Testing: tested on Win10 device

Associated Issues:

skandler commented 4 months ago

will submit a new pull request for the T1003.004 file