LogoClawIndex
CasesSkillsAbout
LogoClawIndex

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.

cyber-detecting-t1003-credential-dumping-with-edr - Detecting T1003 Credential Dumping With EDR

Detect OS credential dumping techniques targeting LSASS memory, SAM, and NTDS using EDR telemetry, Sysmon, and Windows event correlation.

Tags

Updated: 2026-09-17

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Monitor LSASS process access
  • Detect credential dumping tools
  • Monitor NTDS.dit file access
  • Track SAM hive access
  • Detect DCSync activity
  • Correlate lateral movement events

Inputs

  • EDR agent telemetry
  • Sysmon ProcessAccess logs
  • Windows Security event logs
  • Registry auditing logs

Outputs

  • Threat hunting report
  • Credential compromise impact assessment

Requirements

  • EDR agent with LSASS access monitoring
  • Sysmon Event ID 10 with LSASS filters
  • Windows Security Event ID 4656 and 4663 auditing
  • LSASS SACL auditing enabled
  • Registry auditing for SAM hive

Source

  • Spec: SKILL.md
threat-hunting
credential-dumping
lsass
mitre-t1003
edr
Monitor LSASS process access
Detect credential dumping tools
Monitor NTDS.dit file access
Track SAM hive access
EDR agent telemetry
Sysmon ProcessAccess logs
Windows Security event logs
Threat hunting report
Credential compromise impact assessment