Bypass Credential Guard by patching WDigest.dll using only NTAPI functions
-
Updated
Apr 8, 2025 - C++
Bypass Credential Guard by patching WDigest.dll using only NTAPI functions
By manipulating LSASS memory flags like UseLogonCredential and IsCredGuardEnabled, this repo demonstrates how Credential Guard can be bypassed—restoring cleartext credentials despite the protection appearing active. Requires SYSTEM-level access and targets VBS-based defenses.
Disable VBS, HVCI & Device Guard on Windows 11 24H2/25H2 — Fix VMware Workstation "Virtualized Intel VT-x/EPT" & enable CPL0 mode. One-command PowerShell script with auto-elevation, system restore, and auto-verification. 95%+ success rate.
C++ Credential Guard status checker for credential isolation validation
Disable VBS on Windows 11 (24H2/25H2) to enhance performance and enable VMware Workstation CPL0 mode safely and efficiently.
Add a description, image, and links to the credential-guard topic page so that developers can more easily learn about it.
To associate your repository with the credential-guard topic, visit your repo's landing page and select "manage topics."