Attackers who get administrator rights on a server often dump credentials from the memory of the Local Security Authority Subsystem Service (LSASS), then reuse NTLM hashes or Kerberos tickets to move to other machines, known as pass-the-hash and pass-the-ticket. Windows Server has two defenses that protect LSASS: Credential Guard, built on virtualization-based security, and LSA protection.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.