Malicious WDigest UseLogonCredential Enablement for Cleartext Credentials

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-10-01
Updated
2026-10-01

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the WDigest UseLogonCredential value being set to 1, which forces Windows to keep cleartext credentials in memory for later theft. This registry modification was used in the pharmacy intrusion to enable plaintext credential harvesting and is almost never legitimate on modern systems.

Related detections9 linkedT1112 — drag to rearrange
Malicious Restricted Admin Mode Enabled for Pass-the-Hash RDP
Malicious Windows Defender Service Disable via Registry
Suspicious RDP Enablement via fDenyTSConnections Registry Modification
LanmanServer MaxMpxCt Registry Modification for Lateral Movement Preparation
Suspicious RDP Enablement via fDenyTSConnections Registry Modification [Huntress] #2
Malicious Winos 4.0 Configuration and Shellcode Storage in Registry (via registry_set)
Suspicious Service ImagePath Pointing to ShieldNetWork Driver via Registry
Suspicious CredSSP Encryption Oracle Remediation Weakening via Registry (via registry_set)
Malicious Kong RAT Configuration Registry Keys
Malicious WDigest UseLogonCredential Enablement for Cleartext Credentials
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.