Title:Wdigest CredGuard Registry Modification Status:test Description:Detects potential malicious modification of the property value of IsCredGuardEnabled from
HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to disable Cred Guard on a system.
This is usually used with UseLogonCredential to manipulate the caching credentials.
References: -https://teamhydra.blog/2020/08/25/bypassing-credential-guard/ Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) Date: 2019-08-25 modified:2021-11-27 Tags: