Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access

Alerts on rundll32 launching the Windows Key Manager (keymgr / KRShowKeyMgr), a potential credential access step.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-04-21
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process executions where rundll32.exe is invoked with command-line arguments that include keymgr and KRShowKeyMgr, which opens the Windows Stored User Names and Passwords (Key Manager) interface. Attackers may use this to access or expose stored credentials from the Key Manager context. The detection relies on Windows process creation telemetry, matching the image name/path and required command-line substrings.

Related detections5 linkedT1555.004 — drag to rearrange
Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
Suspicious Windows Credential Manager Enumeration (via process_creation)
Uncommon Applications Access Windows DPAPI Master Key Files
Windows Credential History File Access by Uncommon Applications
Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Pivot detection · T1555.004 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.