Windows Process Creation: cmdkey.exe Listing Cached Credentials (-l)

Alerts on cmdkey.exe running with -l to enumerate cached credentials on a Windows host.

FreeUnreviewedSigmahighv1
title: "Windows Process Creation: cmdkey.exe Listing Cached Credentials (-l)"
id: fa37c657-346e-4039-89d9-4f10b66665c7
status: test
description: This rule flags Windows process creation where cmdkey.exe is executed with the -l option to list cached credentials on the system. Attackers may use this to enumerate stored authentication material before attempting credential access or follow-on exploitation. It relies on process creation telemetry capturing the executable identity (Image/OriginalFileName) and the command-line containing ' -l'.
references:
  - https://www.peew.pw/blog/2017/11/26/exploring-cmdkey-an-edge-case-for-privilege-escalation
  - https://technet.microsoft.com/en-us/library/cc754243(v=ws.11).aspx
  - https://github.com/redcanaryco/atomic-red-team/blob/b27a3cb25025161d49ac861cb216db68c46a3537/atomics/T1003.005/T1003.005.md#atomic-test-1---cached-credential-dump-via-cmdkey
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml
author: jmallette, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2019-01-16
modified: 2024-03-05
tags:
  - attack.credential-access
  - attack.t1003.005
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith: \cmdkey.exe
    - OriginalFileName: cmdkey.exe
  selection_cli:
    CommandLine|contains|windash: " -l"
  condition: all of selection*
falsepositives:
  - Legitimate administrative tasks
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_cmdkey_recon/info.yml
simulation:
  - type: atomic-red-team
    name: Cached Credential Dump via Cmdkey
    technique: T1003.005
    atomic_guid: 56506854-89d6-46a3-9804-b7fde90791f9
license: DRL-1.1
related:
  - id: 07f8bdc2-c9b3-472a-9817-5a670b872f53
    type: derived

What it detects

This rule flags Windows process creation where cmdkey.exe is executed with the -l option to list cached credentials on the system. Attackers may use this to enumerate stored authentication material before attempting credential access or follow-on exploitation. It relies on process creation telemetry capturing the executable identity (Image/OriginalFileName) and the command-line containing ' -l'.

Known false positives

  • Legitimate administrative tasks

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.