Windows Credential Manager Enumeration via VaultCmd.exe /listcreds

Flags VaultCmd.exe executions that enumerate saved Windows Credential Manager entries using /listcreds.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-04-08
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects process creation where VaultCmd.exe is executed with the /listcreds option, which enumerates credentials stored in Windows Credential Manager. Attackers may use this built-in utility to discover saved credentials for subsequent credential access. The detection relies on process creation telemetry including the executable name/path and command-line arguments.

Related detections5 linkedT1555.004 — drag to rearrange
Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
Suspicious Windows Credential Manager Enumeration (via process_creation)
Uncommon Applications Access Windows DPAPI Master Key Files
Windows Credential History File Access by Uncommon Applications
Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Pivot detection · T1555.004 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.