PowerShell Credential Manager credential dumping via Get-PasswordVaultCredentials or Get-CredManCreds
Alerts on PowerShell script blocks that invoke Windows Credential Manager credential retrieval functions.
FreeUnreviewedSigmamediumv1
powershell-credential-manager-credential-dumping-via-get-passwordvaultcredential-99c49d9c
title: PowerShell Credential Manager credential dumping via Get-PasswordVaultCredentials or Get-CredManCreds
id: 4750320a-93f4-4655-944b-75e39a45266d
status: test
description: This rule flags PowerShell script block activity that calls credential retrieval functions associated with Windows Credential Manager, specifically Get-PasswordVaultCredentials and Get-CredManCreds. Attackers use these APIs to enumerate stored credentials and potentially obtain passwords for further access or privilege escalation. The detection relies on ScriptBlockText matching combined with object construction patterns that appear when the related Credential Manager access code is present.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1555/T1555.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_dump_password_windows_credential_manager.yml
author: frack113, Huntrule Team
date: 2021-12-20
modified: 2022-12-25
tags:
- attack.credential-access
- attack.t1555
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_kiddie:
ScriptBlockText|contains:
- Get-PasswordVaultCredentials
- Get-CredManCreds
selection_rename_Password:
ScriptBlockText|contains|all:
- New-Object
- Windows.Security.Credentials.PasswordVault
selection_rename_credman:
ScriptBlockText|contains|all:
- New-Object
- Microsoft.CSharp.CSharpCodeProvider
- "[System.Runtime.InteropServices.RuntimeEnvironment]::GetRuntimeDirectory())"
- Collections.ArrayList
- System.CodeDom.Compiler.CompilerParameters
condition: 1 of selection_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 99c49d9c-34ea-45f7-84a7-4751ae6b2cbc
type: derived
What it detects
This rule flags PowerShell script block activity that calls credential retrieval functions associated with Windows Credential Manager, specifically Get-PasswordVaultCredentials and Get-CredManCreds. Attackers use these APIs to enumerate stored credentials and potentially obtain passwords for further access or privilege escalation. The detection relies on ScriptBlockText matching combined with object construction patterns that appear when the related Credential Manager access code is present.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.