Techniques
Sample rules
Windows LAPS Credential Dump From Entra ID
- source: sigma
- technicques:
- t1098
- t1098.005
Description
Detects when an account dumps the LAPS password from Entra ID.
Detection logic
condition: selection
selection:
activityType|contains: Recover device local administrator password
additionalDetails.additionalInfo|contains: Successfully recovered local credential
by device id
category: Device