PowerShell Credential Manager Credential Dump via Script Block Text Matching (Windows)

Alerts on PowerShell script blocks that invoke Windows Credential Manager credential retrieval functions.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-20
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags PowerShell script activity that attempts to retrieve stored credentials from Windows Credential Manager using known cmdlet or provider patterns. Attackers often use these locations to access plaintext or reusable secrets for further account compromise. It relies on Script Block Logging telemetry to match specific PowerShell ScriptBlockText strings indicating credential vault enumeration and related .NET object instantiation behavior.

Related detections9 linkedT1555 — drag to rearrange
Suspicious ALPHA SPIDER Veeam Backup Credential Extraction (via process_creation)
Malicious User Files Dump via Network Share - DonPapi, Lazagne (via security)
Malicious User Application Credentials Dump via Network Share - DonPapi, Lazagne (via security)
Malicious Veeam Credential Theft via PowerShell (via ps_script)
Malicious Credential Harvesting via LaZagne (via process_creation)
Suspicious Credential Prompt Phishing via osascript (via process_creation)
Suspicious Credential Store Access for WinSCP and PuTTY via PowerShell (via ps_script)
Malicious Veeam Credential Extraction via sqlcmd Query (via process_creation)
Suspicious SharpDPAPI Machine Masterkey Extraction (via process_creation)
PowerShell Credential Manager Credential Dump via Script Block Text Matching (Windows)
Pivot detection · T1555 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.