Windows Security Service Execution of Credential Dumping Tools (Event ID 4697)

Alerts on Event ID 4697 service execution paths containing common credential dumping tool names on Windows.

FreeUnreviewedSigmahighv1
title: Windows Security Service Execution of Credential Dumping Tools (Event ID 4697)
id: f243bc7a-fff3-4d94-980f-8ae492573f54
related:
  - id: 4976aa50-8f41-45c6-8b15-ab3fc10e79ed
    type: derived
  - id: f0d1feba-4344-4ca9-8121-a6c97bd6df52
    type: derived
status: test
description: This rule flags Windows service creation/execution events (Security log Event ID 4697) where the service binary path contains well-known credential dumping tool names such as cachedump, pwdump, or gsecdump. Credential dumping tools are commonly used to access sensitive authentication material, and service-based execution can indicate an attacker deploying tooling for credential access. It relies on Windows Security audit telemetry that records Event ID 4697 along with the ServiceFileName value.
references:
  - https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_mal_creddumper.yml
author: Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule Team
date: 2017-03-05
modified: 2022-11-29
tags:
  - attack.credential-access
  - attack.execution
  - attack.t1003.001
  - attack.t1003.002
  - attack.t1003.004
  - attack.t1003.005
  - attack.t1003.006
  - attack.t1569.002
  - attack.s0005
logsource:
  product: windows
  service: security
  definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
detection:
  selection:
    EventID: 4697
    ServiceFileName|contains:
      - cachedump
      - dumpsvc
      - fgexec
      - gsecdump
      - mimidrv
      - pwdump
      - servpw
  condition: selection
falsepositives:
  - Legitimate Administrator using credential dumping tool for password recovery
level: high
license: DRL-1.1

What it detects

This rule flags Windows service creation/execution events (Security log Event ID 4697) where the service binary path contains well-known credential dumping tool names such as cachedump, pwdump, or gsecdump. Credential dumping tools are commonly used to access sensitive authentication material, and service-based execution can indicate an attacker deploying tooling for credential access. It relies on Windows Security audit telemetry that records Event ID 4697 along with the ServiceFileName value.

Known false positives

  • Legitimate Administrator using credential dumping tool for password recovery

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.