Windows CLI Processes Using Common Weak or Abused Passwords

Alerts when Windows command lines include common weak or reused password values.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-09-14
Updated
2026-07-30

What it detects

This rule flags Windows process executions where the command line contains well-known weak or commonly reused password strings. Attackers may use inline credentials when creating or modifying accounts or attempting remote access, making this behavior a useful signal for credential exposure and poor operational hygiene. Detection relies on process creation telemetry, specifically the command-line text captured at process start.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.