Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Win10启用Windows Defender Credential Guard #2

Open
Mount4in opened this issue Apr 11, 2023 · 2 comments
Open

Win10启用Windows Defender Credential Guard #2

Mount4in opened this issue Apr 11, 2023 · 2 comments

Comments

@Mount4in
Copy link

你好,我在Vmware Workstation的win10虚拟机中开启了Windows Defender Credential Guard,我是参考网上的教程,在组策略中启用了Credential Guard,
image

通过msinfo32.exe查看也显示Credential Guard正在运行
image
但是在运行你的BypassCredGuard.exe后仍然显示
image
g_IsCredGuardEnabled变量为0,而且使用mimikatz抓取口令,并没有显示您博客中说的

NTLM 哈希处显示的是 “LSA Isolated Data: NtlmHash”。

想问下您在win10启用Windows Defender Credential Guard是否遇到了这个问题?

@wh0amitz
Copy link
Owner

发一下版本号吧

@Mount4in
Copy link
Author

Windows 22H2 10.0.19045.2006
Windows 22H2 10.0.19045.2604
这两个都没有显示g_IsCredGuardEnabled变量为1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants