Windows DLL image load: credui.dll loaded by an uncommon process
Detects credui.dll or wincredui.dll being loaded by a process other than common system binaries.
- Product
- windows
- Category
- image_load
- Author
- Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
- Published
- 2020-10-20
- Updated
- 2026-07-31
ATT&CK techniques
Cred Access → CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows processes that load credui.dll and wincredui.dll when the loading process is not part of a set of common, expected binaries. Credential UI and related DLLs are often used to prompt for or handle credential data, so unexpected loaders can indicate credential-access tooling or related activity. It relies on image-load telemetry (including the loaded module path and the loader process image) and matches module names via ImageLoaded ending and OriginalFileName.
Reporting behind it
- securitydatasets.comhttps://securitydatasets.com/notebooks/atomic/windows/credential_access/SDWIN-201020013208.html
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.002/T1056.002.md#atomic-test-2---powershell---prompt-user-for-password
- learn.microsoft.comhttps://learn.microsoft.com/en-us/windows/win32/api/wincred/nf-wincred-creduipromptforcredentialsa
- github.comhttps://github.com/S12cybersecurity/RDPCredentialStealer
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_dll_credui_uncommon_process_load.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Windows DLL image load: credui.dll loaded by an uncommon process"
id: d46ebd05-563f-45cc-915b-ea168551a02d
status: test
description: This rule flags Windows processes that load credui.dll and wincredui.dll when the loading process is not part of a set of common, expected binaries. Credential UI and related DLLs are often used to prompt for or handle credential data, so unexpected loaders can indicate credential-access tooling or related activity. It relies on image-load telemetry (including the loaded module path and the loader process image) and matches module names via ImageLoaded ending and OriginalFileName.
references:
- https://securitydatasets.com/notebooks/atomic/windows/credential_access/SDWIN-201020013208.html
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.002/T1056.002.md#atomic-test-2---powershell---prompt-user-for-password
- https://learn.microsoft.com/en-us/windows/win32/api/wincred/nf-wincred-creduipromptforcredentialsa
- https://github.com/S12cybersecurity/RDPCredentialStealer
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_dll_credui_uncommon_process_load.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-10-20
modified: 2026-06-29
tags:
- attack.credential-access
- attack.collection
- attack.t1056.002
logsource:
category: image_load
product: windows
detection:
selection:
- ImageLoaded|endswith:
- \credui.dll
- \wincredui.dll
- OriginalFileName:
- credui.dll
- wincredui.dll
filter_main_generic:
Image|startswith:
- C:\Program Files (x86)\
- C:\Program Files\
- C:\Windows\System32\
- C:\Windows\SysWOW64\
- C:\Windows\SystemApps\
filter_main_full:
Image:
- C:\Windows\explorer.exe
- C:\Windows\ImmersiveControlPanel\SystemSettings.exe
- C:\Windows\regedit.exe
filter_optional_opera:
Image|endswith: \opera_autoupdate.exe
filter_optional_process_explorer:
Image|endswith:
- \procexp64.exe
- \procexp64a.exe
- \procexp.exe
filter_optional_teams:
Image|startswith: C:\Users\
Image|contains: \AppData\Local\Microsoft\Teams\
Image|endswith: \Teams.exe
filter_optional_onedrive:
Image|startswith: C:\Users\
Image|contains: \AppData\Local\Microsoft\OneDrive\
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Other legitimate processes loading those DLLs in your environment.
level: medium
license: DRL-1.1
related:
- id: 9ae01559-cf7e-4f8e-8e14-4c290a1b4784
type: derived