PowerShell Credential Manager Credential Dump via Script Block Text Matching (Windows)
Alerts on PowerShell script blocks that invoke Windows Credential Manager credential retrieval functions.
- Product
- windows
- Category
- ps_script
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2021-12-20
- Updated
- 2026-07-31
ATT&CK techniques
Cred AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script activity that attempts to retrieve stored credentials from Windows Credential Manager using known cmdlet or provider patterns. Attackers often use these locations to access plaintext or reusable secrets for further account compromise. It relies on Script Block Logging telemetry to match specific PowerShell ScriptBlockText strings indicating credential vault enumeration and related .NET object instantiation behavior.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell Credential Manager Credential Dump via Script Block Text Matching (Windows)
id: 4750320a-93f4-4655-944b-75e39a45266d
status: test
description: This rule flags PowerShell script activity that attempts to retrieve stored credentials from Windows Credential Manager using known cmdlet or provider patterns. Attackers often use these locations to access plaintext or reusable secrets for further account compromise. It relies on Script Block Logging telemetry to match specific PowerShell ScriptBlockText strings indicating credential vault enumeration and related .NET object instantiation behavior.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1555/T1555.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_dump_password_windows_credential_manager.yml
author: frack113, Huntrule Team
date: 2021-12-20
modified: 2022-12-25
tags:
- attack.credential-access
- attack.t1555
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_kiddie:
ScriptBlockText|contains:
- Get-PasswordVaultCredentials
- Get-CredManCreds
selection_rename_Password:
ScriptBlockText|contains|all:
- New-Object
- Windows.Security.Credentials.PasswordVault
selection_rename_credman:
ScriptBlockText|contains|all:
- New-Object
- Microsoft.CSharp.CSharpCodeProvider
- "[System.Runtime.InteropServices.RuntimeEnvironment]::GetRuntimeDirectory())"
- Collections.ArrayList
- System.CodeDom.Compiler.CompilerParameters
condition: 1 of selection_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 99c49d9c-34ea-45f7-84a7-4751ae6b2cbc
type: derived