social @ 2025-10-23

SpecterOps released "DumpGuard" along with a detailed article on how they were able to bypass Windows Credential Guard in both privileged and unprivileged contexts. I learned a ton about Isolated LSA and friends. Its funny to see that DES-cracking of NTLMv1 challenges is still relevant (and that ntlmv1.com/ has supplanted crack.sh).

Article: specterops.io/blog/2025/10/23/

DumpGuard: github.com/bytewreck/DumpGuard