Check if Credential Guard is enabled

Description: What does this query look for?

Looks for machines that have credential guard enabled (Windows)

What The Data Shows: What value does this provide, why would I want this information?

Ensuring Credential Guard is enabled protects machines against dumping NTML hashes, Kerberos Ticket Granting Tickets, and credentials stored by applications as domain credentials running attacks such as pass-the-hash.


Select * from processes 
where name like "lsa%so.exe";


This finds all devices that do not have LsaIso.exe running which is the credential guard process. The process only shows up running when Credential Guard is enabled and running. Credential guard can be enabled but doesn't necessarily mean it's running. This confirms the process is running indicating that it's enabled and actually running and working.

