Skip to content

Credential Guard

Credential Guard is the page the rest of this section keeps pointing at. The homepage's worked example ends with it untouched; the bypass matrix draws it above the line a kernel primitive cannot cross; Protected Process Light uses it as the contrast that explains itself. The reason is one architectural fact: the secrets live in VTL1, and a VTL0 kernel read/write primitive, however complete, has no path there.

That makes this inventory the most instructive on the site, because it is the only one where the honest verdict for the headline technique is closed.

Layer User. The protected asset is credential material: hashes, keys, tickets.
Enforced by Hypervisor. LSASS secrets are held by an isolated LSA in VTL1.
Mechanism Isolation, not access control. The data is moved out of reach.
Introduced Windows 10 Enterprise 1607, as a VBS feature; enabled by default on Enterprise from 22H2.

Isolation versus a stored decision

FIG_019: Why the primitive has no path

<text class="ks-label" x="30" y="30">PPL, THE OTHER MODEL</text>
<rect class="ks-box" x="30" y="44" width="360" height="56"/>
<text class="ks-annotation" x="45" y="66">A decision stored in VTL0 kernel memory.</text>
<text class="ks-annotation" x="45" y="84">Kernel write edits the decision. Open.</text>

<text class="ks-label" x="450" y="30">CREDENTIAL GUARD, THIS MODEL</text>
<rect class="ks-box" x="450" y="44" width="340" height="56" stroke-dasharray="4 3"/>
<text class="ks-annotation" x="465" y="66">The secret itself lives in VTL1.</text>
<text class="ks-annotation" x="465" y="84">Kernel write has no address to write. Closed.</text>

<line class="ks-line" x1="415" y1="30" x2="415" y2="220" stroke-dasharray="5 4"/>
<text class="ks-annotation" x="425" y="216">hypervisor boundary, the same line the matrix draws</text>

<text class="ks-annotation" x="30" y="140">The consequence for technique one below: no amount of kernel capability changes the verdict.</text>
<text class="ks-annotation" x="30" y="158">What changes it is not loading: with VBS off, LSA falls back to running in VTL0, and the</text>
<text class="ks-annotation" x="30" y="176">page becomes a note about a defense that is not present. The configuration selector below</text>
<text class="ks-annotation" x="30" y="194">models exactly that, and the first row is why the hardening curve moves.</text>

Bypass inventory

Why the inventory looks like this

The open entry is not a weakness of Credential Guard; it is the boundary of what isolation can mean. A defense that holds secrets can do nothing about an adversary who arranges for the user to hand over a fresh credential, which is why the realistic posture stacks this page on top of LSA Protection for the VBS-off case, and on MFA and relay hardening for the sidestep.

The closed entry deserves its confidence check, which is why it carries basis: inferred rather than cited: it is reasoned from the architecture, matching every public description of the feature, but this corpus has no case study that attempted the direct read and failed against it. If one is ever published, the verdict flips to cited or to a new technique, and this page is where that lands.

What a defender sees

VBS and Credential Guard status reported per machine, which is the cheapest high-value telemetry on this page: the third technique lives or dies by whether VBS is actually on across the fleet. Credential use that succeeds without any corresponding isolated-LSA authentication flow is the signature of the sidestep, and belongs in identity telemetry rather than endpoint telemetry.