Windows Process Creation: cmdkey.exe Listing Cached Credentials (-l)
Alerts on cmdkey.exe running with -l to enumerate cached credentials on a Windows host.
FreeUnreviewedSigmahighv1
windows-process-creation-cmdkey-exe-listing-cached-credentials-l-07f8bdc2
title: "Windows Process Creation: cmdkey.exe Listing Cached Credentials (-l)"
id: fa37c657-346e-4039-89d9-4f10b66665c7
status: test
description: This rule flags Windows process creation where cmdkey.exe is executed with the -l option to list cached credentials on the system. Attackers may use this to enumerate stored authentication material before attempting credential access or follow-on exploitation. It relies on process creation telemetry capturing the executable identity (Image/OriginalFileName) and the command-line containing ' -l'.
references:
- https://www.peew.pw/blog/2017/11/26/exploring-cmdkey-an-edge-case-for-privilege-escalation
- https://technet.microsoft.com/en-us/library/cc754243(v=ws.11).aspx
- https://github.com/redcanaryco/atomic-red-team/blob/b27a3cb25025161d49ac861cb216db68c46a3537/atomics/T1003.005/T1003.005.md#atomic-test-1---cached-credential-dump-via-cmdkey
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml
author: jmallette, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2019-01-16
modified: 2024-03-05
tags:
- attack.credential-access
- attack.t1003.005
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \cmdkey.exe
- OriginalFileName: cmdkey.exe
selection_cli:
CommandLine|contains|windash: " -l"
condition: all of selection*
falsepositives:
- Legitimate administrative tasks
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_cmdkey_recon/info.yml
simulation:
- type: atomic-red-team
name: Cached Credential Dump via Cmdkey
technique: T1003.005
atomic_guid: 56506854-89d6-46a3-9804-b7fde90791f9
license: DRL-1.1
related:
- id: 07f8bdc2-c9b3-472a-9817-5a670b872f53
type: derived
What it detects
This rule flags Windows process creation where cmdkey.exe is executed with the -l option to list cached credentials on the system. Attackers may use this to enumerate stored authentication material before attempting credential access or follow-on exploitation. It relies on process creation telemetry capturing the executable identity (Image/OriginalFileName) and the command-line containing ' -l'.
Known false positives
- Legitimate administrative tasks
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.