Suspicious Windows Credential Manager Enumeration (via process_creation)

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-07-01
Updated
2026-08-28

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects cmdkey /list or vaultcmd /list enumerating saved credentials in the Windows Credential Manager, a credentials-from-password-stores technique used to reveal cached logins for lateral movement. Credential Manager enumeration is tracked in the Red Canary Threat Detection Report. Detecting these commands surfaces stored-credential discovery.

Related detections5 linkedT1555.004 — drag to rearrange
Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
Uncommon Applications Access Windows DPAPI Master Key Files
Windows Credential History File Access by Uncommon Applications
Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Suspicious Windows Credential Manager Enumeration (via process_creation)
Pivot detection · T1555.004 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.