Skip to content

Win10启用Windows Defender Credential Guard #2

@Mount4in

Description

@Mount4in

你好,我在Vmware Workstation的win10虚拟机中开启了Windows Defender Credential Guard,我是参考网上的教程,在组策略中启用了Credential Guard,
image

通过msinfo32.exe查看也显示Credential Guard正在运行
image
但是在运行你的BypassCredGuard.exe后仍然显示
image
g_IsCredGuardEnabled变量为0,而且使用mimikatz抓取口令,并没有显示您博客中说的

NTLM 哈希处显示的是 “LSA Isolated Data: NtlmHash”。

想问下您在win10启用Windows Defender Credential Guard是否遇到了这个问题?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions