To access material, start machines and answer questions login.
One of the most dangerous weapons an attacker can leverage is a valid username and password combination. By obtaining legitimate credentials, an adversary can bypass traditional exploits to log in rather than break in, thereby blending in with normal user traffic. While the ATT&CK technique Valid Accounts (T1078) spans multiple tactics, this room focuses specifically on its role in Initial Access.
Learning Objectives
- Examine why valid account abuse allows adversaries to bypass traditional detections
- Analyze the common techniques adversaries use to harvest valid credentials
- Identify malicious authentication patterns within Windows event logs
- Evaluate forensic artifacts to detect credential-based initial access
- Explore prevention and mitigation methods used to combat valid credential use
Prerequisites
Some familiarity with Windows Event Logs and common remote access services such as and will be useful for this walkthrough. It is also recommended that you understand Windows forensic techniques and artifacts.
- Check out Windows Event Logs for an overview of important event
- Cover Windows User Account Forensics to learn about account types and artifacts
- Go over Expediting Registry Analysis to learn about Windows registry acquisition and analysis
Machine Access
Two machines are attached to this room. The -Storage machine holds the triage the response team collected, and the DefenseBox is your analysis workstation, with the toolkit already installed.
Set up your virtual environment
IR-Storage Credentials
Use these credentials if you are connecting via RDP or when using the net use command
Getting the Evidence
Start the machine above and log in. The collection does not sit on the DefenseBox itself. It sits on the IR storage network share, which is where a response team keeps a case once it has been acquired, and the files are in the Artifacts directory on that IR-Storage host. Copy them across to the DefenseBox.
I understand the learning objectives and am ready to learn about initial access with valid credentials!
Ready to learn Cyber Security?
The Investigating Valid Credentials Abuse room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in
