How quickly can a single exposed service let attackers turn one login into full domain control? That question drove a controlled validation on our Windows estate. We mimicked real-world moves where threat actors abuse exposed Remote Desktop Protocol (RDP), drop an archive with Process Hacker and a credential-dumping tool, then scrape memory for secrets.
We targeted an unprotected server—no VPN, no rate limiting, no multi-factor authentication (MFA). Attackers gained admin creds and moved laterally across the network in minutes. Endpoints guarded by modern EDR blocked the payload and stopped spread.
This defensive exercise revealed where credentials and password material accumulate in memory, why legacy AV misses the behavior, and what teams must monitor now.
For techniques and Windows details on how credentials live in memory, see LSA and credential notes. This work aims to help security teams spot blind spots and harden environments before real attacks exploit them.
Key Takeaways
- One exposed RDP host can let attackers harvest credentials and pivot fast.
- Memory often holds multiple credential types; monitor process behavior, not just files.
- Modern EDR that blocks memory scraping can stop these attacks when tuned correctly.
- Legacy AV and whitelisted RDP traffic create dangerous blind spots.
- Controlled validation on live systems gives the clearest view of real risks.
Why We Ran a Live Test in a Windows Environment
Our team simulated real attacker steps on an operational Windows domain to capture credential-handling signals. The aim was to observe how credential dumping appears in processes, logs, and registry-backed caches so teams can tune detection and response.
Credential theft is a common step in lateral movement. Windows stores secrets across SAM, cached credentials, LSA secrets, and the LSASS process. These places can contain plaintext, NT/LM hashes, and Kerberos tickets.
We tracked where credentials live and what alerts they create. Live validation reveals process reads, Event ID 4688 trails, and shadow copy activity that tabletop exercises miss. After initial access, attackers often steal credentials, copy payloads via PsExec or SMB, run remote binaries, and repeat.
Tests stayed scoped: no destructive actions, focused on evidence from LSASS memory and registry caches. Using open source tools helped us map behaviors defenders should detect, not just filenames.
| Location | Artifact | Common Signals | Suggested Detection |
|---|---|---|---|
| SAM / Registry | Cached hashes | Registry reads, vssadmin use | Monitor registry access, limit shadow copies |
| LSASS memory | Plaintext / NTLM hashes / tickets | Process read attempts, LSASS tamper alerts | EDR LSASS protections, alert on unusual handles |
| Kerberos | Tickets | Ticket reuse, abnormal Kerberos requests | Detect ticket anomalies, restrict delegation |
| Network shares | Copied payloads | PsExec, SMB transfers, 4688 events | Harden file shares, log remote execution |
Outcome: a clearer map from initial access to credential dumping and lateral execution, enabling security and IT teams to validate alerts and close blind spots.
A Case Study of Using Mimikatz to Find Plaintext Passwords
Our team examined LSASS on running hosts to catalog live credential material held in memory. This short, focused validation shows what lives inside the local security authority while users and services are active.
How the tool interacts with the service matters more than the filename it runs from. Mimikatz hooks the security authority subsystem and reads process memory from the authority subsystem service (LSASS). That access exposes active authentication artifacts that enable replay and impersonation.
- Secrets recoverable: plaintext passwords via WDigest/TSPkg/LiveSSP, NT/LM hashes, Kerberos tickets, and sometimes PIN codes stored for convenience.
- Session behavior: credentials memory is tied to active logons; interactive and service sessions populate LSASS and logoff usually clears live material, though residues can remain.
- Beyond dumping: the tool supports pass-the-hash, pass-the-ticket, and Golden Tickets, turning extracted artifacts into lateral movement and domain escalation.
Controls to reduce risk: validate that WDigest’s UseLogonCredential is disabled, enforce least privilege, and avoid interactive logons for high-value accounts. Monitor memory read patterns against the lsass process rather than chasing specific tool names.
Attack Path We Simulated and Observed in the Past
We recreated an end-to-end intrusion to show how one exposed entry point lets attackers escalate and spread within an environment. The timeline highlights where defenders should focus telemetry and controls.
The intrusion started when repeated RDP login retries hit an exposed admin server without MFA.
Initial access via RDP and brute force behavior on exposed services
High-volume RDP brute forcing targeted Patient-0 from unknown internet IPs. The host lacked VPN-only access, rate limiting, and multi-factor protection, so the attacker gained interactive access after repeated attempts.
Dropping open source tools: Mimikatz alongside Process Hacker
Once interactive, the intruder transferred an encrypted archive over the legitimate RDP session. The archive held Process Hacker and an open source credential tool, delivered to blend in with standard admin activity.
Pivoting and lateral movement with valid credentials across the network
Local admin rights let the actor extract credentials, then authenticate into additional hosts via RDP. Repeated remote sessions and remote execution mimicked normal workflows, enabling rapid lateral movement within network segments.
Bypassing legacy AV and “living off the land” techniques
Legacy AV missed the behavior because RDP traffic was whitelisted and signature checks don’t catch memory scraping. Behavioral EDR, however, detected suspicious process lineage and memory reads, quarantining the payload and stopping further spread.
- Telemetry to capture: failed and successful RDP logons, rapid cross-host authentications, unusual process spawns, and account lockouts.
- Residual risk: one harvested hash or ticket can enable follow-on access if segmentation and monitoring are weak.
What We Found in Memory: Credentials, Tickets, and Hashes
Our live memory snapshot exposed multiple active secrets inside the LSASS process during routine interactive sessions. The capture confirmed plaintext credentials, numerous hashes, and reusable Kerberos tickets that attackers could leverage immediately.
Key findings:
- Dozens of plaintext credentials were visible when WDigest was enabled or when services cached logon material. These items were tied to interactive sessions.
- We recorded many NT/LM hashes. Each hash can enable pass-the-hash authentication across hosts without the original password string.
- Kerberos tickets in memory allowed short-term impersonation. With domain controller access and NTDS.DIT extraction via shadow copies, attackers can move toward forging golden tickets.
- Background services sometimes kept credential artifacts after logoff, extending exposure within network segments and helping an intruder move laterally.
Defensive notes: reduce what LSASS holds, validate WDigest is disabled, confirm Credential Guard, and alert on pass-the-hash and anomalous Kerberos tickets. For further technique details, see this advanced credential dumping write-up.
Detection, Containment, and Forensics Signals
Spot behavior that indicates credential theft and act fast to contain lateral spread. Focus on memory reads, suspicious process chains, and shadow copy activity to prioritize response.
The clearest early signals come from process-level reads against LSASS and unusual execution chains. These signs matter more than file names for reliable detection.
EDR alerts and suspicious process creation
Watch for direct handles on the lsass process and unusual child processes. Prioritize behavior-based alerts that flag attempts to read or dump the lsass process. Blocked PowerShell scripts that fetch open source tools from the internet should raise immediate suspicion.
Event and telemetry clues
Monitor Event ID 4688 for strange chains: PowerShell spawning unsigned binaries, archive utilities running from temp, or PsExec calls. Track vssadmin activity; shadow copy creation often precedes directory extraction.
Domain controller targeting
NTDS.DIT, SAM, and SYSTEM hive access usually follows shadow copy use. Look for volume shadow copy manipulation and psexecsvc.exe service creation on remote hosts.
- Containment: isolate hosts, stop malicious processes, rotate exposed credentials.
- Forensics: collect volatile memory and export logs before remediation steps alter evidence.
- Validation: run safe simulations to confirm alerts for LSASS tampering and PsExec abuse.
| Signal | Indicator | Recommended action |
|---|---|---|
| LSASS handles | EDR tamper alert, abnormal process read | Quarantine host, capture memory, alert SOC |
| Process creation | Event ID 4688 showing PowerShell → unsigned binary | Block binary, investigate parent process, hunt lateral traces |
| Shadow copy | vssadmin list/create and NTDS access | Lock down VSS, snapshot evidence, revoke credentials |
| Remote exec | PsExec usage, psexecsvc.exe on targets | Disable service, scan for further access, escalate containment |
Hardening Against Credential Theft in Windows Operating Systems
Lock down remote administration first; public-facing logons give attackers the shortest path to credentials. Reduce exposure, and combine policy with behavior-based detection to raise cost for attackers.
Start by treating every remote login as high risk and assume credentials in memory are valuable targets.
Reduce exposed services and enforce stronger access
Remove public RDP where possible. Place remaining admin access behind VPN and require multi-factor authentication (MFA).
Apply rate limits and account lockouts to frustrate brute force. These steps cut the easiest paths attackers use to move laterally.
Limit privileged session exposure
Avoid interactive logons with domain or tier-0 accounts on shared hosts. That prevents high-value secrets from populating the local security authority or the lsass process on internet-facing systems.
Use Credential Guard, LAPS, and cached credential limits
Enable Credential Guard where supported to isolate the security authority subsystem and protect the authority subsystem service from direct memory reads.
Standardize unique local admin passwords with Microsoft LAPS, rotate them, and reduce cached domain logons to lower reuse risk. Strong password policies increase cracking time if hashes are exfiltrated.
Detect behavior, not just tool names
Block suspicious memory reads to sensitive processes and watch for remote execution patterns like PsExec and shadow copy manipulation.
Focus detection on process-level behavior so open source tools and renamed binaries cannot hide attacks. Segment admin tiers and use just-in-time access to shorten credential utility.
| Control | What it protects | Action |
|---|---|---|
| RDP restrictions | Public exposure, brute force | Remove public RDP, VPN + MFA, rate limits |
| Credential Guard | LSASS process, memory scraping | Enable on supported systems, validate isolation |
| Microsoft LAPS | Local admin credential reuse | Unique passwords, regular rotation |
| Behavior detection | Tool-agnostic attacks | Alert on LSASS handles, remote exec, shadow copies |
Operate defensively as a habit: run controlled simulations to confirm alerts for LSASS tampering and PsExec abuse, educate admins on risky login habits, and treat hardening as ongoing work to reduce drift.
Conclusion
The experiment proved that simple remote access paths often yield the richest rewards for malicious actors.
Live validation revealed plaintext and hashed credentials in memory that could enable rapid lateral movement across a Windows network.
Central finding: during controlled testing we observed credentials and tickets exposed in process memory, enabling quick access and follow-on attacks.
Practical steps: close unnecessary admin exposure, enforce MFA and rate limits, and deploy behavior-driven EDR that flags LSASS tampering and unusual Event ID 4688 chains.
Quick wins include disabling plaintext caching, enabling Credential Guard where supported, and rolling unique local admin secrets with LAPS. Watch for shadow copy activity and registry hive access that may precede NTDS.DIT theft on a domain controller.
Map current detections against these techniques, fix gaps, and re-test regularly. For additional field notes and an attack write-up, see this detailed write-up.