Windows Credential History File Access by Uncommon Applications

Alerts on CREDHIST file access from unexpected application images, indicating potential credential history theft.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_access
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-10-17
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags file access to the Windows Credential History file (ending with \Microsoft\Protect\CREDHIST) when initiated by an application path that is not commonly seen among standard system directories. Credential history data is sensitive, and unusual access patterns can indicate attempts to collect or decrypt credential material. It relies on Windows file access telemetry that includes the accessed filename and the initiating process image path.

Related detections5 linkedT1555.004 — drag to rearrange
Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
Suspicious Windows Credential Manager Enumeration (via process_creation)
Uncommon Applications Access Windows DPAPI Master Key Files
Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Windows Credential History File Access by Uncommon Applications
Pivot detection · T1555.004 · 5 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.