Malicious WDigest UseLogonCredential Enablement For Credential Theft

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-05-09
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the registry modification that sets WDigest UseLogonCredential to 1, forcing Windows to keep cleartext credentials in LSASS memory. The Qilin ransomware group enables this before dumping credentials to escalate and move laterally. Re-enabling plaintext credential caching is a deliberate precursor to LSASS harvesting.

Related detections9 linkedT1003.001 — drag to rearrange
Malicious WDigest UseLogonCredential Enabled for Cleartext Credential Caching
Windows PUA: MemProcFS memory dump mounting via -device
Windows LSASS Process Clone Execution Observed
Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Malicious LSASS Credential Dump via ProcDump (via process_creation)
Suspicious Remote Desktop Enabled via fDenyTSConnections Registry by Sandworm
Malicious LSASS Memory Dump via comsvcs.dll by Salt Typhoon
Malicious Gh0stBins RAT Registry Marker HHClient
Suspicious PebbleDash C2 Configuration Stored Under WMI Security Key (via registry_set)
Malicious WDigest UseLogonCredential Enablement For Credential Theft
Pivot detection · T1003.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.