Windows Logon Session Types: NewCredentials
Logon Type — NewCredentials Used with RunAs or mapping a network drive with alternate credentials. Create a new logon session for the same user but...
Henry Zhang
:
Sep 1, 2024 10:30:00 AM
Provides users given this permission the ability to utilize applications or processes to abuse the credential manager in an attempt to grab credentials for other users on the system. This setting is normally exclusively used by the credential manager during Backup and Restore and should not be assigned to other users.
Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment
Access Credential Manager as a trusted caller
SeTrustedCredManAccessPrivilege
Mitre ATT&CK: Credential Access (TA0006)
STIG: V-220956
Logon Type — NewCredentials Used with RunAs or mapping a network drive with alternate credentials. Create a new logon session for the same user but...
Logon Type — NetworkCleartext Used to logon with credentials sent in clear text (only possible for certain services).
In this part of the Senteon and CIS Webinar Series, Ray Feldman of LastPass continued to highlight the power of aligning CIS Benchmarks with advanced