Windows CLI Enumeration of 3rd-Party Credential Registry Keys

Alerts when Windows processes use command-line queries to enumerate credential-containing third-party registry keys.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-06-20
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process creation where the command line queries a set of known third-party application registry paths that can store credentials. Attackers may enumerate these locations to locate password material prior to credential access or offline collection. It relies on Windows process creation telemetry, matching command-line content against the specified registry subkey strings, while excluding a reg.exe export/save pattern.

Related detections4 linkedT1552.002 — drag to rearrange
Suspicious Registry Query for Stored Credentials (via process_creation)
Windows reg.exe Registry Save/Export of Third-Party Credential Paths
Windows reg.exe Credential Enumeration via Registry Query (HKLM/HKCU)
Windows Security Event 4656: SAM Registry Hive Key Handle Requested
Windows CLI Enumeration of 3rd-Party Credential Registry Keys
Pivot detection · T1552.002 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.