Skip to main content

Investigating Valid Credentials Abuse

Investigate initial access with valid credentials through log data and forensic artifacts.

Back to all walkthroughs
Room Icon

Investigating Valid Credentials Abuse

Max room.

Investigate initial access with valid credentials through log data and forensic artifacts.

medium

90 min

136

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

One of the most dangerous weapons an attacker can leverage is a valid username and password combination. By obtaining legitimate credentials, an adversary can bypass traditional exploits to log in rather than break in, thereby blending in with normal user traffic. While the ATT&CK technique Valid Accounts (T1078) spans multiple tactics, this room focuses specifically on its role in Initial Access.

Learning Objectives

  • Examine why valid account abuse allows adversaries to bypass traditional detections
  • Analyze the common techniques adversaries use to harvest valid credentials
  • Identify malicious authentication patterns within Windows event logs
  • Evaluate forensic artifacts to detect credential-based initial access
  • Explore prevention and mitigation methods used to combat valid credential use

Prerequisites

Some familiarity with Windows Event Logs and common remote access services such as and will be useful for this walkthrough. It is also recommended that you understand Windows forensic techniques and artifacts.

Machine Access

Two machines are attached to this room. The -Storage machine holds the triage the response team collected, and the DefenseBox is your analysis workstation, with the toolkit already installed.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your DefenseBox and Lab Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Defender machine
Status:Off
Lab machine
Status:Off

IR-Storage Credentials

Use these credentials if you are connecting via RDP or when using the net use command

Username
 
Administrator
 
Password
 
Secure!
 
IP address
 
MACHINE_IP 

Getting the Evidence

Start the machine above and log in. The collection does not sit on the DefenseBox itself. It sits on the IR storage network share, which is where a response team keeps a case once it has been acquired, and the files are in the Artifacts directory on that IR-Storage host. Copy them across to the DefenseBox. 

Answer the questions below

I understand the learning objectives and am ready to learn about initial access with valid credentials!