<p><strong>Windows Defender Credential Guard </strong>uses virtualization-based security to isolate secrets so that only privileged system software can access them. Unauthorized access to these secrets can lead to credential theft attacks, such as Pass-the-Hash or Pass-The-Ticket. Windows Defender Credential Guard prevents these attacks by protecting NTLM password hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials.<br>Credential Guard feature also leverages Virtual Secure Mode by placing an isolated version of the Local Security Authority (LSA – or LSASS) under <g class="gr_ gr_13 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling multiReplace" id="13" data-gr-id="13">it’s</g> protection.</p>



<p>Once this is done, you can easily check if Credential Guard (or many of the other features from this article) is enabled by launching MSINFO32.EXE and viewing the following information:<br></p>



<figure class="wp-block-image"><img src="http://www.thecloudxperts.co.uk/wp-content/uploads/2018/10/image_thumb_73005E0F.png" alt="" class="wp-image-339"/><figcaption><br>MSINFO32.EXE</figcaption></figure>



<h3 class="wp-block-heading" id="hardware-and-software-requirements">Hardware and software requirements for <g class="gr_ gr_19 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="19" data-gr-id="19">Credintial</g> Guard</h3>



<p>To provide basic protections against OS level attempts to read Credential Manager domain credentials, NTLM and Kerberos derived credentials, Windows Defender Credential Guard uses:</p>



<ul class="wp-block-list"><li>Support for Virtualization-based security (required)</li><li>Secure boot (required)</li><li>TPM 1.2 or 2.0, either discrete or firmware (preferred &#8211; provides binding to hardware)</li><li>UEFI lock (preferred &#8211; prevents attacker from disabling with a simple registry key change)</li></ul>



<p>The Virtualization-based security requires:</p>



<ul class="wp-block-list"><li>64-bit CPU</li><li>CPU virtualization extensions plus extended page tables</li><li>Windows hypervisor</li></ul>



<h1 class="wp-block-heading" id="device-guard-windows-defender-application-control-and-virtualization-based-protection-of-code-integrity">Device Guard: Windows Defender</h1>



<p><strong>Device Guard</strong> is one of Windows security features that is a combination of enterprise-related hardware, firmware, and software security features. When configured together, it will lock down a <strong>device</strong> so that it can only run trusted applications.</p>



<p>Device Guard consists of three primary components:</p>



<ul class="wp-block-list"><li><strong>Configurable Code Integrity (CCI)</strong> ;– Ensures that only trusted code runs from the boot loader onwards.</li><li><strong>VSM Protected Code Integrity</strong> ;– Moves Kernel Mode Code Integrity (KMCI) and Hypervisor Code Integrity (HVCI) components into VSM, hardening them from attack.</li><li><strong>Platform and UEFI Secure Boot</strong> ;– Ensuring the boot binaries and UEFI firmware are signed and have not been tampered with.</li></ul>



<p>When these features are enabled together, the system is protected by Device Guard, providing class leading malware resistance in Windows 10.</p>



<p>References: <br><a href="https://channel9.msdn.com/Blogs/Seth-Juarez/Isolated-User-Mode-in-Windows-10-with-Dave-Probert">https://channel9.msdn.com/Blogs/Seth-Juarez/Isolated-User-Mode-in-Windows-10-with-Dave-Probert</a><br><a href="https://channel9.msdn.com/Blogs/Seth-Juarez/Isolated-User-Mode-Processes-and-Features-in-Windows-10-with-Logan-Gabriel">https://channel9.msdn.com/Blogs/Seth-Juarez/Isolated-User-Mode-Processes-and-Features-in-Windows-10-with-Logan-Gabriel</a><br><a href="https://channel9.msdn.com/Blogs/Seth-Juarez/Isolated-User-Mode-in-Windows-10-with-Dave-Probert">https://channel9.msdn.com/Blogs/Seth-Juarez/Isolated-User-Mode-in-Windows-10-with-Dave-Probert</a></p>

