Windows DLL image load: credui.dll loaded by an uncommon process

Detects credui.dll or wincredui.dll being loaded by a process other than common system binaries.

FreeReviewedSigma · Medium · v2
Product
windows
Category
image_load
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
Published
2020-10-20
Updated
2026-07-31
title: "Windows DLL image load: credui.dll loaded by an uncommon process"
id: d46ebd05-563f-45cc-915b-ea168551a02d
status: test
description: This rule flags Windows processes that load credui.dll and wincredui.dll when the loading process is not part of a set of common, expected binaries. Credential UI and related DLLs are often used to prompt for or handle credential data, so unexpected loaders can indicate credential-access tooling or related activity. It relies on image-load telemetry (including the loaded module path and the loader process image) and matches module names via ImageLoaded ending and OriginalFileName.
references:
  - https://securitydatasets.com/notebooks/atomic/windows/credential_access/SDWIN-201020013208.html
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1056.002/T1056.002.md#atomic-test-2---powershell---prompt-user-for-password
  - https://learn.microsoft.com/en-us/windows/win32/api/wincred/nf-wincred-creduipromptforcredentialsa
  - https://github.com/S12cybersecurity/RDPCredentialStealer
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/image_load/image_load_dll_credui_uncommon_process_load.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-10-20
modified: 2026-06-29
tags:
  - attack.credential-access
  - attack.collection
  - attack.t1056.002
logsource:
  category: image_load
  product: windows
detection:
  selection:
    - ImageLoaded|endswith:
        - \credui.dll
        - \wincredui.dll
    - OriginalFileName:
        - credui.dll
        - wincredui.dll
  filter_main_generic:
    Image|startswith:
      - C:\Program Files (x86)\
      - C:\Program Files\
      - C:\Windows\System32\
      - C:\Windows\SysWOW64\
      - C:\Windows\SystemApps\
  filter_main_full:
    Image:
      - C:\Windows\explorer.exe
      - C:\Windows\ImmersiveControlPanel\SystemSettings.exe
      - C:\Windows\regedit.exe
  filter_optional_opera:
    Image|endswith: \opera_autoupdate.exe
  filter_optional_process_explorer:
    Image|endswith:
      - \procexp64.exe
      - \procexp64a.exe
      - \procexp.exe
  filter_optional_teams:
    Image|startswith: C:\Users\
    Image|contains: \AppData\Local\Microsoft\Teams\
    Image|endswith: \Teams.exe
  filter_optional_onedrive:
    Image|startswith: C:\Users\
    Image|contains: \AppData\Local\Microsoft\OneDrive\
  condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
  - Other legitimate processes loading those DLLs in your environment.
level: medium
license: DRL-1.1
related:
  - id: 9ae01559-cf7e-4f8e-8e14-4c290a1b4784
    type: derived