Windows Credential Dump Tool Artifacts Written to Disk via File Events
Detects Windows file creation where the target filename contains or ends with known credential-dump tool or output names.
- Product
- windows
- Category
- file_event
- Author
- Teymur Kheirkhabarov, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2019-11-01
- Updated
- 2026-07-31
ATT&CK techniques
Cred AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows file creation or access events where the target filename matches well-known credential dumping tool artifacts and output files. Attackers commonly write these log, DLL/EXE, and credential-related dump outputs to disk during credential access and offline extraction. It relies on Windows file event telemetry that includes the target filename so specific substrings and known filename endings can be matched.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Credential Dump Tool Artifacts Written to Disk via File Events
id: 6f896860-050a-4135-91b4-56182c9256fa
status: test
description: This rule flags Windows file creation or access events where the target filename matches well-known credential dumping tool artifacts and output files. Attackers commonly write these log, DLL/EXE, and credential-related dump outputs to disk during credential access and offline extraction. It relies on Windows file event telemetry that includes the target filename so specific substrings and known filename endings can be matched.
references:
- https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_cred_dump_tools_dropped_files.yml
author: Teymur Kheirkhabarov, oscd.community, Huntrule Team
date: 2019-11-01
modified: 2025-10-25
tags:
- attack.credential-access
- attack.t1003.001
- attack.t1003.002
- attack.t1003.003
- attack.t1003.004
- attack.t1003.005
logsource:
category: file_event
product: windows
detection:
selection:
- TargetFilename|contains:
- \fgdump-log
- \kirbi
- \pwdump
- \pwhashes
- \wce_ccache
- \wce_krbtkts
- TargetFilename|endswith:
- \cachedump.exe
- \cachedump64.exe
- \DumpExt.dll
- \DumpSvc.exe
- \Dumpy.exe
- \fgexec.exe
- \lsremora.dll
- \lsremora64.dll
- \NTDS.out
- \procdump.exe
- \procdump64.exe
- \procdump64a.exe
- \pstgdump.exe
- \pwdump.exe
- \SAM.out
- \SECURITY.out
- \servpw.exe
- \servpw64.exe
- \SYSTEM.out
- \test.pwd
- \wceaux.dll
condition: selection
falsepositives:
- Legitimate Administrator using tool for password recovery
level: high
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_cred_dump_tools_dropped_files/info.yml
license: DRL-1.1
related:
- id: 8fbf3271-1ef6-4e94-8210-03c2317947f6
type: derived