Malicious WDigest UseLogonCredential Enabled for Cleartext Credential Caching

PremiumReviewedSigma · High · v1
Category
registry_set
Author
HuntRule
Published
2026-05-22
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the WDigest UseLogonCredential registry value being set to 1, forcing Windows to cache plaintext credentials in memory as documented by Huntress. Attackers enable this setting before dumping LSASS so that cleartext passwords are recoverable. This modification undermines credential protection and is a strong precursor to credential harvesting.

Related detections9 linkedT1003.001 — drag to rearrange
Malicious WDigest UseLogonCredential Enablement For Credential Theft
Malicious LSASS Credential Dump via ProcDump (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Malicious LSASS Memory Dump via comsvcs.dll by Salt Typhoon
Malicious Gh0stBins RAT Registry Marker HHClient
Suspicious PebbleDash C2 Configuration Stored Under WMI Security Key (via registry_set)
Suspicious WDigest UseLogonCredential Enablement for Plaintext Credential Theft (via registry_set)
Malicious LSASS Dump via Process Access (via process_access)
Malicious LSASS Credential Dump with LSASSY - Process (via process_creation)
Malicious WDigest UseLogonCredential Enabled for Cleartext Credential Caching
Pivot detection · T1003.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.