Jump to content

Credential Guard in non Enterprise version of Windows 10

Hi

I was browsing group policy editor and I have stumbled upon Windows Defender Credential Guard. I was faintly aware of this feature but I didn't know it was present in Pro version of Windows. I have enabled it and lo and behold it appeared under Core Isolation sub menu. Sadly my skills are insufficient to verify weather it's actually work. The way I understand it it protects admin credentials by encrypting them so if malware exploited some system level app it couldn't use those credentials cause there is an extra verification step before access is granted. I don't know how useful it is in a home environment but it would be good to know that it;s there.

Can someone shine some light on the subject pretty please.

Thanks in advance.
Link to comment
Share on other sites

Link to post
Share on other sites

IIRC this is a defense against Mimikatz. You could download metasploit and see if mimi works

5950X/3080Ti primary rig  |  1920X/1070Ti Unraid for dockers  |  200TB TrueNAS w/ 1:1 backup

Link to comment
Share on other sites

Link to post
Share on other sites

Is there some guide out there to follow cause like I said I currently lack the know how to verify if this exploit is patched by Credential Guard. It's not like there is a handy simple gui with the metasploit framework.

 

Ps, I did some more research and it seams Credential Guard protects your doman credentials so not very useful for workgroup/home users. I was curious why such a feature would be exclusive for Enterprise and that explains a lot.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×