Windows cmdkey.exe Adds Generic Credentials via -g Flag

Flags -g/-u/-p with cmdkey.exe indicate generic credential insertion, which can enable follow-on access.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-02-03
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies process executions of cmdkey.exe where the command line includes the generic-credential flag (-g), along with user (-u) and password (-p) arguments. Attackers can use cmdkey.exe to pre-stage credentials for later access to remote resources, reducing the need to supply credentials interactively. It relies on Windows process creation telemetry that records the executable path/name and full command line arguments.

Related detections7 linkedT1003.005 — drag to rearrange
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Windows Cmdkey.EXE Cached Credential Reconnaissance
Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Windows cmdkey.exe Adds Generic Credentials via -g Flag
Pivot detection · T1003.005 · 7 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.