PowerShell Credential Manager credential dumping via Get-PasswordVaultCredentials or Get-CredManCreds

Alerts on PowerShell script blocks that invoke Windows Credential Manager credential retrieval functions.

FreeUnreviewedSigmamediumv1
title: PowerShell Credential Manager credential dumping via Get-PasswordVaultCredentials or Get-CredManCreds
id: 4750320a-93f4-4655-944b-75e39a45266d
status: test
description: This rule flags PowerShell script block activity that calls credential retrieval functions associated with Windows Credential Manager, specifically Get-PasswordVaultCredentials and Get-CredManCreds. Attackers use these APIs to enumerate stored credentials and potentially obtain passwords for further access or privilege escalation. The detection relies on ScriptBlockText matching combined with object construction patterns that appear when the related Credential Manager access code is present.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1555/T1555.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_dump_password_windows_credential_manager.yml
author: frack113, Huntrule Team
date: 2021-12-20
modified: 2022-12-25
tags:
  - attack.credential-access
  - attack.t1555
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection_kiddie:
    ScriptBlockText|contains:
      - Get-PasswordVaultCredentials
      - Get-CredManCreds
  selection_rename_Password:
    ScriptBlockText|contains|all:
      - New-Object
      - Windows.Security.Credentials.PasswordVault
  selection_rename_credman:
    ScriptBlockText|contains|all:
      - New-Object
      - Microsoft.CSharp.CSharpCodeProvider
      - "[System.Runtime.InteropServices.RuntimeEnvironment]::GetRuntimeDirectory())"
      - Collections.ArrayList
      - System.CodeDom.Compiler.CompilerParameters
  condition: 1 of selection_*
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: 99c49d9c-34ea-45f7-84a7-4751ae6b2cbc
    type: derived

What it detects

This rule flags PowerShell script block activity that calls credential retrieval functions associated with Windows Credential Manager, specifically Get-PasswordVaultCredentials and Get-CredManCreds. Attackers use these APIs to enumerate stored credentials and potentially obtain passwords for further access or privilege escalation. The detection relies on ScriptBlockText matching combined with object construction patterns that appear when the related Credential Manager access code is present.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.