Windows: Logged-On User Password Change via ksetup.exe

Flags ksetup.exe executions with /ChangePassword that may indicate a logged-on user password change on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-06
Updated
2026-07-31

What it detects

This rule identifies password change activity where the process image is ksetup.exe and the command line includes the /ChangePassword parameter for the logged-on user context. Attackers may use native Windows utilities to make credential changes while blending into legitimate administrative behavior. The detection relies on process creation telemetry, specifically the executed executable name/path and the command-line content indicating a password change.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.