LAB 643 – Response: Detecting a Malicious Windows Service (NEW)

Course Overview


Uncover the tactics adversaries use to steal credentials and learn how to stop them. In this lab, you’ll use MITRE ATT&CK techniques to analyze Windows logs, detect credential dumping, and strengthen identity protections.

After completing this lab, learners will have the knowledge and skill to:

  • Identify credential access techniques (T1003, T1555)
  • Analyze event logs and memory artifacts
  • Correlate attacker behavior to MITRE mappings
  • Implement defensive measures against credential theft

Looking To Learn More?

Request more information on our courses and labs.

* required


Course Details

Course Number: LAB 643
Course Duration: 5 minutes
Course CPE Credits: 0.1

NICE Work Role Category

Available Languages

  • English