Malicious WDigest Credential Caching Enabled via Registry (via registry_set)

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-12
Updated
2026-09-12

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the WDigest UseLogonCredential value being set to 1, forcing plaintext credentials back into LSASS memory, as done by Lazarus in Operation Blacksmith. Re-enabling WDigest caching prepares the host for subsequent LSASS memory theft of cleartext passwords.

Related detections9 linkedT1003.001 — drag to rearrange
Malicious WDigest UseLogonCredential Enabled for Cleartext Credential Caching
Malicious WDigest UseLogonCredential Enablement For Credential Theft
Malicious Credential Dumping via Mimikatz Sekurlsa Command
Malicious Mimikatz Sekurlsa Logonpasswords Credential Dump
Malicious LSASS Credential Dump via ProcDump (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Malicious LSASS Memory Dump via comsvcs.dll by Salt Typhoon
Malicious Gh0stBins RAT Registry Marker HHClient
Suspicious PebbleDash C2 Configuration Stored Under WMI Security Key (via registry_set)
Malicious WDigest Credential Caching Enabled via Registry (via registry_set)
Pivot detection · T1003.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.