detecting-t1003-credential-dumping-with-edr
mukul975/Anthropic-Cybersecurity-Skills
Use EDR telemetry, Sysmon, and Windows auditing to detect T1003 credential dumping via LSASS, SAM, NTDS, and cached credentials, then correlate lateral movement indicators and guide response actions.