DumpGuard is a proof-of-concept credential-dumping tool released on GitHub as part of research into extracting authentication material from fully patched Windows 11 and Windows Server 2025 systems, including environments protected by Credential Guard, Protected Process Light, and Virtualization-Based Security. Rather than performing traditional LSASS memory dumping, it abuses Remote Credential Guard-related interfaces and LSA authentication package interactions to obtain Kerberos-derived artifacts and NTLM challenge responses. The research showed that an unprivileged attacker can extract their own credentials in crackable NTLMv1 form by simulating a remote host with a machine account or another SPN-bearing account, while SYSTEM privileges allow extraction for other authenticated users as well. A separate SYSTEM-level technique used the Microsoft v1.0 authentication package to obtain NTLMv1 responses for users authenticated locally or through Remote Credential Guard on a server. The work demonstrated use of KerbCredIsoRemote and NtlmCredIsoRemote invocation primitives, crafted CredSSP and MS-RDPEAR structures, and LsaCallAuthenticationPackage to drive Credential Guard-related operations. The static NTLM challenge 1122334455667788 was highlighted as a detection opportunity because resulting NTLMv1 responses can be cracked to recover NT hashes, enabling follow-on abuse such as Pass-the-Hash and Kerberos RC4-based attacks. The content also notes DumpGuard was observed as one of several tools deployed alongside HRSword, PCHunter, Gmer, YDark, WKTools, and StpProcessMonitor BYOVD in a Trigona-linked intrusion, where such tools were used to disable or interfere with endpoint protections.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A utility used by the attackers as part of a broader defense-evasion toolkit in the ransomware intrusion.
A proof-of-concept tool developed to interact with Remote Credential Guard and Credential Guard-related interfaces to extract NTLM responses and Kerberos-related material from modern Windows environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.