Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
Flags appcmd.exe executions that include password-related listing parameters for IIS service account credentials.
- Product
- windows
- Category
- process_creation
- Author
- Tim Rauch, Janantha Marasinghe, Elastic (original idea) (SigmaHQ), DRL 1.1
- Published
- 2022-11-08
- Updated
- 2026-07-31
ATT&CK techniques
Cred AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events where the IIS command-line tool (appcmd.exe) is executed with arguments consistent with listing passwords. Attackers may use AppCmd to enumerate or extract IIS service account credentials during credential access and privilege escalation. The detection relies on Windows process creation telemetry, matching the appcmd.exe image name and specific command-line patterns such as list operations, configuration/XML flags, and password indicators.
Reporting behind it
- elastic.cohttps://www.elastic.co/guide/en/security/current/microsoft-iis-service-account-password-dumped.html
- twitter.comhttps://twitter.com/0gtweet/status/1588815661085917186?cxt=HHwWhIDUyaDbzYwsAAAA
- netspi.comhttps://www.netspi.com/blog/technical/network-penetration-testing/decrypting-iis-passwords-to-break-out-of-the-dmz-part-2/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_iis_appcmd_service_account_password_dumped.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
id: bfdf4321-a467-46a4-8ff3-8b12811482ff
status: test
description: This rule flags process creation events where the IIS command-line tool (appcmd.exe) is executed with arguments consistent with listing passwords. Attackers may use AppCmd to enumerate or extract IIS service account credentials during credential access and privilege escalation. The detection relies on Windows process creation telemetry, matching the appcmd.exe image name and specific command-line patterns such as list operations, configuration/XML flags, and password indicators.
references:
- https://www.elastic.co/guide/en/security/current/microsoft-iis-service-account-password-dumped.html
- https://twitter.com/0gtweet/status/1588815661085917186?cxt=HHwWhIDUyaDbzYwsAAAA
- https://www.netspi.com/blog/technical/network-penetration-testing/decrypting-iis-passwords-to-break-out-of-the-dmz-part-2/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_iis_appcmd_service_account_password_dumped.yml
author: Tim Rauch, Janantha Marasinghe, Elastic (original idea), Huntrule Team
date: 2022-11-08
modified: 2023-01-22
tags:
- attack.credential-access
- attack.t1003
logsource:
category: process_creation
product: windows
detection:
selection_base_name:
- Image|endswith: \appcmd.exe
- OriginalFileName: appcmd.exe
selection_base_list:
CommandLine|contains: "list "
selection_standalone:
CommandLine|contains:
- " /config"
- " /xml"
- " -config"
- " -xml"
selection_cmd_flags:
CommandLine|contains:
- " /@t"
- " /text"
- " /show"
- " -@t"
- " -text"
- " -show"
selection_cmd_grep:
CommandLine|contains:
- :\*
- password
condition: all of selection_base_* and (selection_standalone or all of selection_cmd_*)
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 2d3cdeec-c0db-45b4-aa86-082f7eb75701
type: derived