Windows Security EID 4697 Service Execution of Credential Dumping Tools

Alerts on Event ID 4697 service execution paths containing common credential dumping tool names on Windows.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
Published
2017-03-05
Updated
2026-07-31

ATT&CK techniques

Execution → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows Security audit events (EventID 4697) where a service is created and the service binary path/name contains well-known credential dumping tool indicators such as cachedump, dumpsvc, fgexec, gsecdump, mimidrv, pwdump, or servpw. Credential dumping is a common attacker objective for accessing credentials and escalating privileges. The detection relies on Security log telemetry for service creation events that include the referenced service file name.

Related detections9 linkedT1003.002 — drag to rearrange
Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Windows Event Logs: Mimikatz Keyword Indicators
Windows PUA: MemProcFS memory dump mounting via -device
Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Malicious Mimikatz Credential Access Module Invocation
Zeek SMB: Network Share File Transfers of Credential-Related Filenames
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Pivot detection · T1003.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.