Testing a 58864D MOSFET confirms a short between drain and source
A 58864D MOSFET is being tested for a short circuit between the drain and source terminals. Measurements taken from drain to source and then from source to drain produce the same shorted result. This abnormal reading indicates that the MOSFET has failed internally and is shorted between drain and source. This repair image is an independent work sample and is not an illustration of the educational subject discussed below.

Understanding Credential Guard

Compromising One Computer Could Lead to Another

An attacker who gained control of a Windows computer did not necessarily have to stop there.

The compromised system could contain authentication material belonging to users who had signed in, including highly privileged accounts with access to other computers and network resources.

Those credentials could become a path deeper into the organization.

The First Computer Could Be Only the Beginning

If valuable authentication material could be extracted from one compromised endpoint, attackers could attempt to reuse it against additional systems rather than independently breaking into every computer.

An Attacker Did Not Always Need to Know the Actual Password

Windows authentication involves more than the characters a user types at the sign-in screen.

Systems may work with password-derived information, Kerberos tickets, and other authentication material that allows users to access network resources without repeatedly entering their passwords.

That convenience creates valuable secrets in memory.

Protecting the Password Alone Was Not Enough

An attacker who obtains usable authentication material may be able to impersonate an account without ever recovering or learning the user’s original plaintext password.

A Password Hash Could Sometimes Be Reused Instead of Cracked

A password hash is normally thought of as something an attacker would try to crack in order to recover the original password.

But certain Windows authentication attacks created a more immediate possibility. Rather than discovering the password first, an attacker could attempt to use the captured NTLM hash itself as authentication material.

This became known as pass-the-hash.

Cracking and Reusing Are Different Attacks

If a protocol accepts authentication derived from the captured hash, the attacker may not need to determine the original password before attempting to impersonate the account.

A Credential in RAM Could Be Worth More Than a Password Written Down

Authentication material present on a running computer can become an attractive target after an attacker gains sufficient local privileges.

Tools designed for credential theft may attempt to inspect sensitive processes and extract information that can later be used to authenticate elsewhere.

The attack moves from the local machine toward the network.

Local Compromise Could Become Network Identity Theft

Once reusable authentication material is extracted, the attacker may attempt to operate as the legitimate account against other computers and services that trust those credentials.

Network Authentication Could Be Stolen Without Taking the Password

Active Directory environments commonly use Kerberos to authenticate users to network resources.

Kerberos relies on tickets that allow authenticated users to request access to services without repeatedly transmitting their account password. Those tickets therefore become valuable targets when attackers compromise a workstation.

The authentication session itself can contain useful material.

A Ticket Can Represent Authority

Authentication tickets need protection because possession of usable ticket material can allow an attacker to impersonate an authenticated identity without entering the account’s original password.

An Administrator Signing Into the Wrong Computer Could Leave Something Valuable Behind

IT administrators frequently need to work on many computers.

If a highly privileged account authenticates on a machine that is already compromised, malware on that endpoint may attempt to capture authentication material associated with the administrator’s session.

The attacker’s privilege can suddenly expand.

The Value of a Compromised PC Depends on Who Uses It

A workstation with limited local importance can become strategically valuable when an administrator or another privileged user signs in and introduces credentials capable of reaching more sensitive systems.

The Objective Was Often to Move Across the Network

Attackers rarely choose their first compromised computer because it contains everything they ultimately want.

The initial endpoint may simply provide a foothold. From there, stolen credentials can help attackers reach file servers, administrative systems, additional workstations, and eventually more valuable infrastructure.

Credential theft enables movement.

Identity Can Become the Attacker’s Transportation

Once attackers obtain credentials trusted elsewhere in the environment, legitimate authentication mechanisms may help them move between systems without exploiting a new software vulnerability at every step.

Protecting Credentials Inside the Same Kernel Had Limits

Sensitive authentication information had traditionally existed within the Windows operating environment.

That creates a difficult situation after a deep compromise. Malware operating with sufficiently powerful privileges may attempt to inspect or manipulate parts of the operating system responsible for authentication.

The secrets needed another boundary.

Privilege Can Defeat Software Boundaries

When an attacker reaches highly privileged execution within the operating system, protections implemented entirely inside that same environment can become more difficult to defend against tampering and memory inspection.

The Hypervisor Could Create a Protected Security Environment

Windows 10 expanded the purpose of hardware virtualization beyond running virtual machines.

Virtualization-based security could use the Hyper-V hypervisor and processor virtualization capabilities to establish an isolated environment separate from the ordinary Windows kernel.

Selected security functions could operate behind that boundary.

Virtualization Became Part of Credential Protection

Credential Guard uses virtualization-based security to isolate authentication secrets so they are not exposed to ordinary Windows in the same way they would be without the protected environment.

Kernel Privilege Did Not Automatically Mean Access to Everything

A conventional Windows process depends on the kernel to enforce its memory boundaries.

Virtualization-based security adds another level of isolation beneath ordinary Windows. The hypervisor can protect selected memory so the normal operating system does not simply receive unrestricted access to it.

The security boundary moves below the kernel.

The Operating System Could Be Separated From Its Own Secrets

Credential Guard was designed so valuable authentication material could remain protected by virtualization even if malware obtained powerful privileges within the normal Windows environment.

Windows Could Use Credentials Without Exposing Them Normally

The Local Security Authority plays a central role in Windows authentication.

Credential Guard changes how selected secrets used by authentication are protected. Sensitive material can be isolated while Windows communicates with the protected component when authentication operations are required.

The system can use the credential without treating it like ordinary accessible memory.

Use Does Not Have to Mean Direct Access

Isolation allows the normal operating system to request authentication operations while keeping selected credential material behind a stronger boundary rather than exposing the secret directly to every privileged component.

Pass the Hash Became Harder When the Hash Was Harder to Reach

Pass-the-hash attacks depend on obtaining useful password-derived authentication material.

Credential Guard protects NTLM password hashes by isolating them through virtualization-based security. This reduces the ability of malware running in normal Windows to simply extract those secrets and carry them elsewhere.

The attack loses an important source of reusable material.

Preventing Theft Can Be Better Than Detecting Reuse

If the credential cannot be extracted from the compromised computer in the first place, the attacker has less authentication material available for subsequent pass-the-hash attempts against other systems.

Ticket Theft Also Faced the Virtualization Boundary

Credential Guard also protects valuable Kerberos authentication material, including Ticket Granting Tickets.

That matters because a TGT can be used as part of requesting access to services on behalf of an authenticated user. Protecting it reduces another path by which a local compromise can become broader identity theft.

The defense covers more than one protocol.

Microsoft Protects Both NTLM and Kerberos Material

Credential Guard is designed to protect NTLM password hashes and Kerberos Ticket Granting Tickets, addressing two important categories of Windows domain authentication secrets.

A Captured Ticket Could Otherwise Be Used Without the Password

Pass-the-ticket attacks demonstrate why password protection alone cannot solve credential theft.

If an attacker obtains appropriate Kerberos ticket material, that material may provide a route to impersonation without requiring the original password to be entered or recovered.

Credential Guard aims to protect the ticket before it can be stolen.

Authentication Artifacts Can Be Credentials

Anything that allows a system to prove identity or obtain authenticated access deserves protection even when it does not resemble a conventional username and password.

Owning Windows Did Not Necessarily Mean Owning the Security Boundary

Kernel-level malware remains extremely dangerous.

But virtualization-based security changes the assumption that compromising the normal Windows kernel automatically provides unrestricted access to every valuable security resource on the machine.

The attacker can encounter another privilege boundary beneath Windows.

The Highest Windows Privilege Was No Longer the Highest Platform Privilege

By placing selected security functions behind the hypervisor, Windows 10 could create resources that ordinary kernel-mode code was not intended to access directly.

Credential Isolation Depended on the Platform Beneath Windows

Virtualization-based security requires appropriate processor and firmware capabilities.

Hardware virtualization, Secure Boot, and related platform protections contribute to establishing and maintaining the isolated environment. The strength of the design therefore extends below Windows itself.

Software alone does not create the entire boundary.

The Processor Became Part of the Security Model

Credential Guard relies on platform virtualization capabilities to establish isolation that ordinary application or process permissions cannot provide by themselves.

The Hypervisor Needed to Start From a Trusted Foundation

Isolation created after an attacker already controls the startup environment would provide a weaker security foundation.

Secure Boot helps establish trust during the early boot process by restricting unauthorized startup components, supporting the environment in which virtualization-based security can operate.

Credential protection begins before the user signs in.

Early Trust Supports Later Isolation

Hardware-backed credential protection depends on establishing trustworthy platform components before ordinary Windows begins handling the authentication activity Credential Guard is intended to protect.

The Computer Could Still Be Compromised

Isolating credentials does not make malware harmless.

An attacker controlling a Windows computer may still access files available to the signed-in user, manipulate applications, capture information displayed on the screen, install persistence, or perform many other damaging actions.

Credential Guard addresses a specific high-value problem.

Protecting Credentials Does Not Protect Everything

Credential Guard reduces opportunities for certain credential-theft attacks, but organizations still need malware protection, patching, least privilege, network controls, secure administration, and other defensive layers.

One Compromised Endpoint Did Not Need to Expose Every Account That Touched It

Security architecture often assumes that some systems will eventually be compromised.

The important question then becomes how much additional damage that compromise permits. Protecting authentication secrets can reduce the attacker’s ability to convert control of one workstation into reusable identities for attacking others.

Containment limits the value of the foothold.

A Breach Can Be Serious Without Becoming Universal

Credential isolation helps separate compromise of the endpoint from compromise of every reusable authentication secret associated with users who interact with that endpoint.

Privileged Accounts Should Not Wander Through Untrusted Systems

Credential Guard strengthens protection, but administrative discipline remains important.

Highly privileged accounts should be used carefully because authentication activity can expose organizations to risks beyond the credential types protected by any one technology.

Reducing unnecessary privileged sign-ins reduces opportunity.

Separate Administration From Everyday Computing

Using dedicated administrative workflows and limiting where privileged credentials are presented can reduce the number of systems from which attackers might attempt to capture valuable authentication material.

Some Authentication Methods Expected Direct Access to Credentials

Credential isolation changes assumptions that older authentication mechanisms and applications may have made.

Microsoft notes that some protocols cannot use the signed-in credentials while Credential Guard is enabled. Organizations therefore need to test authentication requirements before broad deployment.

Stronger isolation can expose legacy dependencies.

Security Architecture Can Affect Compatibility

Applications and network services that depend on older authentication behavior may require different credentials, updated configuration, or modernization when Credential Guard prevents access to protected sign-in secrets.

Convenience Historically Required Credentials to Remain Available

Users expect to sign in once and then access multiple network resources without repeatedly typing their passwords.

Providing that experience requires Windows to maintain enough authentication state to prove the user’s identity when additional services are requested.

Credential Guard had to preserve useful authentication while protecting the underlying secrets.

Security Had to Preserve Normal Work

The objective was not simply to erase credentials after sign-in but to isolate selected secrets while allowing supported authentication mechanisms to continue operating through controlled interfaces.

The Same Virtualization Architecture Could Protect Different Assets

Windows 10 used virtualization-based security for more than one defensive purpose.

Device Guard could use protected Code Integrity to strengthen decisions about which software was trusted to execute. Credential Guard used the virtualization boundary to protect valuable authentication material.

The protected assets were different, but the architectural idea was related.

Credential Guard

Uses virtualization-based security to isolate selected authentication secrets and reduce credential theft.

Protected Code Integrity

Uses virtualization-based isolation to strengthen the environment responsible for deciding which code is trusted to execute.

The Best Reusable Password Is Sometimes No Reusable Password

Credential Guard protects important authentication secrets after users sign in, but Windows 10 was also beginning to change how users authenticated in the first place.

Microsoft Passport and Windows Hello introduced device-bound authentication approaches that could reduce dependence on conventional reusable passwords.

The two strategies attacked credential theft from different directions.

Protect Existing Secrets and Reduce the Need for Them

Credential isolation makes valuable authentication material harder to steal, while device-bound passwordless authentication can reduce reliance on reusable passwords that attackers traditionally target.

Protected Credentials Did Not Make an Authenticated User Invisible

If malware is running while a user is actively working, the attacker may attempt to abuse the user’s existing access rather than steal the underlying credential.

For example, malicious code may try to perform actions in the context of an already authenticated session or manipulate resources the user can legitimately reach.

Credential isolation cannot eliminate every form of impersonation.

Protecting the Key Does Not Stop Every Use of an Open Door

Credential Guard helps protect reusable authentication secrets, but compromise of an active endpoint can still expose resources and capabilities already available to the signed-in user.

An Attacker Needed More Than Powerful Windows Permissions

The important shift was architectural.

Rather than relying entirely on access-control rules inside the same Windows environment that malware might compromise, Credential Guard placed selected secrets behind virtualization-based isolation.

The attacker had another security boundary to defeat.

Isolation Changes What Compromise Automatically Provides

A deeply compromised operating system remains dangerous, but separating valuable credentials from ordinary Windows reduces the assumption that kernel-level access automatically exposes every authentication secret on the machine.

Stolen Identity Should Not Become a Shortcut Across the Network

Pass-the-hash and pass-the-ticket attacks are powerful because they allow authentication material taken from one system to be used against another.

Credential Guard aimed to interrupt that process at the source by making important reusable secrets more difficult to extract from the compromised endpoint.

Preventing theft reduces what can be replayed.

Compromising the computer did not have to mean carrying every valuable credential out with you.

Credential Guard Put Authentication Secrets Behind a Boundary Windows Itself Could Not Simply Cross

Windows 10 Credential Guard addressed a problem that had become increasingly important in enterprise attacks: the ability to steal authentication material from one compromised computer and use it to impersonate legitimate accounts elsewhere.

Instead of relying entirely on protections inside the normal Windows kernel, Credential Guard uses virtualization-based security to isolate valuable secrets. Microsoft identifies NTLM password hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials among the material protected by the feature.

The result did not make a compromised workstation safe, nor did it eliminate the need for careful administration and other defensive layers. What changed was the assumption that powerful access to Windows automatically provided equally powerful access to every reusable authentication secret. The hypervisor could place another security boundary between the attacker and the credentials that might otherwise help turn one compromised computer into many.