Chad Tilbury has been responding to computer intrusions and conducting forensic investigations since 1998. As Technical Director for CrowdStrike, he provides technical leadership for the services team, driving innovation to support customers in a variety of services, including incident response, remediation, forensic support, penetration testing, intelligence operations, and compromise assessment. He has worked with a broad cross-section of Fortune 500 corporations and government agencies around the world, including service as a Special Agent with the US Air Force Office of Special Investigations. Chad is a Senior Instructor at the SANS Institute and co-author of their FOR408 and FOR508 courses. Windows credentials are arguably the largest vulnerability affecting the modern enterprise. Credential harvesting is goal number one post-exploitation, and hence it provides an appealing funnel point for identifying attacks early in the kill chain. Credentials are diverse and numerous in Windows, and so are the attacks. Older vulnerabilities like pass the hash, token stealing, and cached credentials still plague modern enterprises. Added to these are a seemingly endless supply of new attacks on Kerberos authentication. No network can be secured without strong credential management. Microsoft released significant credential theft mitigations in Win8.1, Win10 and Server 2012/2016, and both red and blue teams must quickly update their skills accordingly. Red teamers may suddenly find their favorite techniques obsolete, and will need to adapt to ensure new implementations are tested. Even more important, defenders need to take advantage of newly available mitigation techniques and update credential protection processes immediately. Attendees will leave this workshop with a deep understanding of Windows credential vulnerabilities, along with knowledge of attack tools and techniques currently used to exploit them. Particular attention will be given to mitigating and detecting threats, focusing limited resources, and evaluating new improvements to the Microsoft credential model. Documentation and reference materials will be provided.