Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)

Triggers on AV signatures matching PWS* or known credential-dumping tool strings indicating potential password theft activity.

FreeReviewedSigma · Critical · v5
Category
antivirus
Author
Florian Roth (Nextron Systems), Arnim Rupp (SigmaHQ), DRL 1.1
Published
2018-09-09
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags antivirus alerts whose signature indicates password dumper or credential-stealing activity, based on signature prefixes and specific tool-name substrings. Attackers use these tools to extract credentials from local systems, making this behavior critical for credential-access investigations even if the malware was blocked. The detection relies on antivirus alert telemetry containing the matched signature string (Signature).

Related detections9 linkedT1003.001 — drag to rearrange
Windows PUA: MemProcFS memory dump mounting via -device
Renamed Mimikatz Credential Theft Command Indicators (via process_creation)
Malicious Mimikatz Credential Access Module Invocation
Malicious WDigest UseLogonCredential Enablement For Credential Theft
Windows LSASS Process Clone Execution Observed
Zeek SMB: Network Share File Transfers of Credential-Related Filenames
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Windows Network Share File Transfers Targeting Credential and Memory Dump Paths
Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Pivot detection · T1003.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.