Windows Security Service Execution of Credential Dumping Tools (Event ID 4697)
Alerts on Event ID 4697 service execution paths containing common credential dumping tool names on Windows.
FreeUnreviewedSigmahighv1
windows-security-service-execution-of-credential-dumping-tools-event-id-4697-f0d1feba
title: Windows Security Service Execution of Credential Dumping Tools (Event ID 4697)
id: f243bc7a-fff3-4d94-980f-8ae492573f54
related:
- id: 4976aa50-8f41-45c6-8b15-ab3fc10e79ed
type: derived
- id: f0d1feba-4344-4ca9-8121-a6c97bd6df52
type: derived
status: test
description: This rule flags Windows service creation/execution events (Security log Event ID 4697) where the service binary path contains well-known credential dumping tool names such as cachedump, pwdump, or gsecdump. Credential dumping tools are commonly used to access sensitive authentication material, and service-based execution can indicate an attacker deploying tooling for credential access. It relies on Windows Security audit telemetry that records Event ID 4697 along with the ServiceFileName value.
references:
- https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_mal_creddumper.yml
author: Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule Team
date: 2017-03-05
modified: 2022-11-29
tags:
- attack.credential-access
- attack.execution
- attack.t1003.001
- attack.t1003.002
- attack.t1003.004
- attack.t1003.005
- attack.t1003.006
- attack.t1569.002
- attack.s0005
logsource:
product: windows
service: security
definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
detection:
selection:
EventID: 4697
ServiceFileName|contains:
- cachedump
- dumpsvc
- fgexec
- gsecdump
- mimidrv
- pwdump
- servpw
condition: selection
falsepositives:
- Legitimate Administrator using credential dumping tool for password recovery
level: high
license: DRL-1.1
What it detects
This rule flags Windows service creation/execution events (Security log Event ID 4697) where the service binary path contains well-known credential dumping tool names such as cachedump, pwdump, or gsecdump. Credential dumping tools are commonly used to access sensitive authentication material, and service-based execution can indicate an attacker deploying tooling for credential access. It relies on Windows Security audit telemetry that records Event ID 4697 along with the ServiceFileName value.
Known false positives
- Legitimate Administrator using credential dumping tool for password recovery
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.