LAB 643 – Response: Detecting a Malicious Windows Service (NEW)
Course Overview
Uncover the tactics adversaries use to steal credentials and learn how to stop them. In this lab, you’ll use MITRE ATT&CK techniques to analyze Windows logs, detect credential dumping, and strengthen identity protections.
After completing this lab, learners will have the knowledge and skill to:
- Identify credential access techniques (T1003, T1555)
- Analyze event logs and memory artifacts
- Correlate attacker behavior to MITRE mappings
- Implement defensive measures against credential theft
Looking To Learn More?
Request more information on our courses and labs.
* required

Course Details
Course Number: LAB 643
Course Duration: 5 minutes
Course CPE Credits: 0.1
NICE Work Role Category
Available Languages
- English