Unguarding Microsoft Credential Guard | SO-CON 2025

Unguarding Microsoft Credential Guard | SO-CON 2025

Source: YouTube · SpecterOps · published May 8, 2025 · 46:17

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Kerry, a Principal Security Consultant at Netsy, details her technical analysis of Microsoft Credential Guard, focusing on secure kernel isolation mechanisms and demonstrating automated debugging and credential bypass techniques 0:05.

Key Takeaways:
• Kerry transitioned from 18 years in software development to cybersecurity in 2019, now splitting her time 50/50 between R&D and red team operations 0:05.
• Credential Guard protects secrets like NTLM hashes and Kerberos keys using LSA ISO trustlets in VTL1, isolating them from the normal world 2:30.
• Windows 24H2 broke previous debugging methods by removing the hypervisor's con section and the SKPSIsDebugEnabled function 4:30.
• Kerry developed an automated GDB scripting technique using IDTR caching scans and VMCS reads to bypass 24H2 changes and debug LSA ISO 5:30.
• She added features to Rubeus to request service tickets via LSA, bypassing Credential Guard by manipulating the SPN format hint to use an X500 distinguished name 12:00.
• Microsoft patched this bypass in January 2025 by adding stricter checks for the "krbtgt" Common Name within service tickets 13:30.

This presentation highlights the evolving cat-and-mouse game between advanced offensive tools and Microsoft's defensive updates to Credential Guard.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Music] Thank you for all coming to my talk on guarding Microsoft credential guard. So a little bit about myself. Uh my name is Kerry. I'm from Wales in the United Kingdom. Um us Welsh do tend to speak fast. So um apologies in advance if you're struggling to keep up. Uh so my background is in software development. I was there for 18 years sort of in the DRM and security solutions space and then back in 2019 I transitioned to to to cyber and I'm currently a principal security consultant at at Netsy. So my role at Net Spy is split sort of 50/50. So half of that is R&D and then the other half is on sort of red team operations. But I don't particularly I'm not particularly the primary operator in any of those engagements. I usually get pulled in to sort of um help out on any obscure sort of so…