Windows Registry Access to WCESERVICE Start Key

Detects registry activity targeting the WCE service Start configuration in Windows.

FreeReviewedSigma · Critical · v1
Product
windows
Category
registry_event
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-12-31
Updated
2026-07-30
title: Windows Registry Access to WCESERVICE Start Key
id: a723c790-559f-4b3f-ae84-d6d37286fa70
status: test
description: This rule flags registry events where the TargetObject path contains Services\WCESERVICE\Start, consistent with activity related to the Windows Credential Editor service start setting. Attackers may use WCE to access or manipulate credentials, so monitoring service-related registry paths helps catch credential-access tooling deployment or activation. It relies on Windows registry event telemetry that includes the TargetObject field.
references:
  - https://www.ampliasecurity.com/research/windows-credentials-editor/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_event/registry_event_hack_wce_reg.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2019-12-31
modified: 2021-11-27
tags:
  - attack.credential-access
  - attack.t1003.001
  - attack.s0005
logsource:
  category: registry_event
  product: windows
detection:
  selection:
    TargetObject|contains: Services\WCESERVICE\Start
  condition: selection
falsepositives:
  - Unknown
level: critical
license: DRL-1.1
related:
  - id: a6b33c02-8305-488f-8585-03cb2a7763f2
    type: derived