Windows Credential Dump Tool Artifacts Written to Disk via File Events

Detects Windows file creation where the target filename contains or ends with known credential-dump tool or output names.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Teymur Kheirkhabarov, oscd.community (SigmaHQ), DRL 1.1
Published
2019-11-01
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows file creation or access events where the target filename matches well-known credential dumping tool artifacts and output files. Attackers commonly write these log, DLL/EXE, and credential-related dump outputs to disk during credential access and offline extraction. It relies on Windows file event telemetry that includes the target filename so specific substrings and known filename endings can be matched.

Related detections9 linkedT1003.002 — drag to rearrange
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Windows PUA: MemProcFS memory dump mounting via -device
Zeek SMB: Network Share File Transfers of Credential-Related Filenames
Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Windows Network Share File Transfers Targeting Credential and Memory Dump Paths
Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Pivot detection · T1003.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.