Demystify: Windows 10 Device Guard Windows Defender Credential Guard

Sharing is caring!

&NewLine;<p><strong>Windows Defender Credential Guard <&sol;strong>uses virtualization-based security to isolate secrets so that only privileged system software can access them&period; Unauthorized access to these secrets can lead to credential theft attacks&comma; such as Pass-the-Hash or Pass-The-Ticket&period; Windows Defender Credential Guard prevents these attacks by protecting NTLM password hashes&comma; Kerberos Ticket Granting Tickets&comma; and credentials stored by applications as domain credentials&period;<br>Credential Guard feature also leverages Virtual Secure Mode by placing an isolated version of the Local Security Authority &lpar;LSA – or LSASS&rpar; under <g class&equals;"gr&lowbar; gr&lowbar;13 gr-alert gr&lowbar;spell gr&lowbar;inline&lowbar;cards gr&lowbar;run&lowbar;anim ContextualSpelling multiReplace" id&equals;"13" data-gr-id&equals;"13">it’s<&sol;g> protection&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Once this is done&comma; you can easily check if Credential Guard &lpar;or many of the other features from this article&rpar; is enabled by launching MSINFO32&period;EXE and viewing the following information&colon;<br><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><img src&equals;"http&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2018&sol;10&sol;image&lowbar;thumb&lowbar;73005E0F&period;png" alt&equals;"" class&equals;"wp-image-339"&sol;><figcaption><br>MSINFO32&period;EXE<&sol;figcaption><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<h3 class&equals;"wp-block-heading" id&equals;"hardware-and-software-requirements">Hardware and software requirements for <g class&equals;"gr&lowbar; gr&lowbar;19 gr-alert gr&lowbar;spell gr&lowbar;inline&lowbar;cards gr&lowbar;run&lowbar;anim ContextualSpelling ins-del multiReplace" id&equals;"19" data-gr-id&equals;"19">Credintial<&sol;g> Guard<&sol;h3>&NewLine;&NewLine;&NewLine;&NewLine;<p>To provide basic protections against OS level attempts to read Credential Manager domain credentials&comma; NTLM and Kerberos derived credentials&comma; Windows Defender Credential Guard uses&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Support for Virtualization-based security &lpar;required&rpar;<&sol;li><li>Secure boot &lpar;required&rpar;<&sol;li><li>TPM 1&period;2 or 2&period;0&comma; either discrete or firmware &lpar;preferred &&num;8211&semi; provides binding to hardware&rpar;<&sol;li><li>UEFI lock &lpar;preferred &&num;8211&semi; prevents attacker from disabling with a simple registry key change&rpar;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>The Virtualization-based security requires&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>64-bit CPU<&sol;li><li>CPU virtualization extensions plus extended page tables<&sol;li><li>Windows hypervisor<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<h1 class&equals;"wp-block-heading" id&equals;"device-guard-windows-defender-application-control-and-virtualization-based-protection-of-code-integrity">Device Guard&colon; Windows Defender<&sol;h1>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Device Guard<&sol;strong> is one of Windows security features that is a combination of enterprise-related hardware&comma; firmware&comma; and software security features&period; When configured together&comma; it will lock down a <strong>device<&sol;strong> so that it can only run trusted applications&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Device Guard consists of three primary components&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li><strong>Configurable Code Integrity &lpar;CCI&rpar;<&sol;strong>&nbsp&semi;– Ensures that only trusted code runs from the boot loader onwards&period;<&sol;li><li><strong>VSM Protected Code Integrity<&sol;strong>&nbsp&semi;– Moves Kernel Mode Code Integrity &lpar;KMCI&rpar; and Hypervisor Code Integrity &lpar;HVCI&rpar; components into VSM&comma; hardening them from attack&period;<&sol;li><li><strong>Platform and UEFI Secure Boot<&sol;strong>&nbsp&semi;– Ensuring the boot binaries and UEFI firmware are signed and have not been tampered with&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>When these features are enabled together&comma; the system is protected by Device Guard&comma; providing class leading malware resistance in Windows 10&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>References&colon; <br><a href&equals;"https&colon;&sol;&sol;channel9&period;msdn&period;com&sol;Blogs&sol;Seth-Juarez&sol;Isolated-User-Mode-in-Windows-10-with-Dave-Probert">https&colon;&sol;&sol;channel9&period;msdn&period;com&sol;Blogs&sol;Seth-Juarez&sol;Isolated-User-Mode-in-Windows-10-with-Dave-Probert<&sol;a><br><a href&equals;"https&colon;&sol;&sol;channel9&period;msdn&period;com&sol;Blogs&sol;Seth-Juarez&sol;Isolated-User-Mode-Processes-and-Features-in-Windows-10-with-Logan-Gabriel">https&colon;&sol;&sol;channel9&period;msdn&period;com&sol;Blogs&sol;Seth-Juarez&sol;Isolated-User-Mode-Processes-and-Features-in-Windows-10-with-Logan-Gabriel<&sol;a><br><a href&equals;"https&colon;&sol;&sol;channel9&period;msdn&period;com&sol;Blogs&sol;Seth-Juarez&sol;Isolated-User-Mode-in-Windows-10-with-Dave-Probert">https&colon;&sol;&sol;channel9&period;msdn&period;com&sol;Blogs&sol;Seth-Juarez&sol;Isolated-User-Mode-in-Windows-10-with-Dave-Probert<&sol;a><&sol;p>&NewLine;

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.