Windows Security Event 4661 Password Policy Enumeration via ReadPasswordParameters

Flags Windows Event 4661 activity indicating password policy enumeration (ReadPasswordParameters on Security Account Manager).

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Zach Mathis (SigmaHQ), DRL 1.1
Published
2023-05-19
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags Windows Security auditing events where a handle request includes the ReadPasswordParameters access (%%5392) against the Security Account Manager. Enumerating the password policy can help an attacker understand local authentication requirements and guide subsequent attacks. It relies on Windows Security log event 4661 telemetry with the specific access right and object server context.

Related detections6 linkedT1201 — drag to rearrange
Suspicious Secedit Security Policy Export for Reconnaissance (via process_creation)
PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Windows process creation: CrackMapExec execution via characteristic command-line flags
Linux Password Policy Discovery via chage and passwd Commands
Cisco AAA discovery via show/dir commands
Windows Process Creation: Execution of Net.exe or Net1.exe
Windows Security Event 4661 Password Policy Enumeration via ReadPasswordParameters
Pivot detection · T1201 · 6 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.