{"id":"T1555.004","name":"Windows Credential Manager","url":"https://attack.mitre.org/techniques/T1555/004","tactics":["credential-access"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0134","stix_id":"x-mitre-detection-strategy--119f2b00-82ac-41fb-96ac-728bf56a8a29","name":"Detect Suspicious Access to Windows Credential Manager","url":"https://attack.mitre.org/detectionstrategies/DET0134","analytics":[{"id":"AN0378","stix_id":"x-mitre-analytic--207b58a9-7e3b-41ca-bb5a-c66b24210a83","name":"Analytic 0378","description":"Detects unauthorized access to Windows Credential Manager through anomalous process execution (vaultcmd.exe, rundll32.exe keymgr.dll), suspicious API calls (CredEnumerateA), or direct file access to Credential Locker files. Correlates process creation with subsequent file reads of .vcrd/.vpol files under user Credential Locker directories.","url":"https://attack.mitre.org/detectionstrategies/DET0134#AN0378","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredPaths","description":"Credential Locker paths such as %Systemdrive%\\Users\\*\\AppData\\Local\\Microsoft\\Credentials and %Systemdrive%\\Users\\*\\AppData\\Local\\Microsoft\\Vault"},{"field":"TimeWindow","description":"Correlation window between process execution, file access, and API calls"},{"field":"PrivilegedUsers","description":"Baseline of expected administrative/service accounts with legitimate Credential Manager access"}],"live":true,"detection_strategies":["DET0134"],"techniques":["T1555.004"]}],"live":true,"version":"1.0","techniques":["T1555.004"]}],"sigma_rules":[{"id":"46612ae6-86be-4802-bc07-39b59feb1309","title":"Access To Windows DPAPI Master Keys By Uncommon Applications","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-17","modified":"2026-07-28","description":"Detects file access requests to the the Windows Data Protection API Master keys by an uncommon application.\nThis can be a sign of credential stealing. Example case would be usage of mimikatz \"dpapi::masterkey\" function\n","references":["http://blog.harmj0y.net/redteaming/operational-guidance-for-offensive-user-dpapi-abuse/","https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/dpapi-extracting-passwords"],"logsource":{"product":"windows","category":"file_access"},"tags":["attack.credential-access","attack.t1555.004"],"path":"rules/windows/file/file_access/file_access_win_susp_dpapi_master_key_access.yml","techniques":["T1555.004"],"cves":[]},{"id":"58f50261-c53b-4c88-bd12-1d71f12eda4c","title":"Windows Credential Manager Access via VaultCmd","author":"frack113","status":"test","level":"medium","date":"2022-04-08","modified":"2022-05-13","description":"List credentials currently stored in Windows Credential Manager via the native Windows utility vaultcmd.exe","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1555.004/T1555.004.md#atomic-test-1---access-saved-credentials-via-vaultcmd"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1555.004"],"path":"rules/windows/process_creation/proc_creation_win_vaultcmd_list_creds.yml","techniques":["T1555.004"],"cves":[]},{"id":"7a2a22ea-a203-4cd3-9abf-20eb1c5c6cd2","title":"Access To Windows Credential History File By Uncommon Applications","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-17","modified":"2024-07-29","description":"Detects file access requests to the Windows Credential History File by an uncommon application.\nThis can be a sign of credential stealing. Example case would be usage of mimikatz \"dpapi::credhist\" function\n","references":["https://tools.thehacker.recipes/mimikatz/modules/dpapi/credhist","https://www.passcape.com/windows_password_recovery_dpapi_credhist"],"logsource":{"product":"windows","category":"file_access"},"tags":["attack.credential-access","attack.t1555.004"],"path":"rules/windows/file/file_access/file_access_win_susp_credhist.yml","techniques":["T1555.004"],"cves":[]},{"id":"a4694263-59a8-4608-a3a0-6f8d3a51664c","title":"Suspicious Key Manager Access","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-21","modified":"2023-02-09","description":"Detects the invocation of the Stored User Names and Passwords dialogue (Key Manager)","references":["https://twitter.com/NinjaParanoid/status/1516442028963659777"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1555.004"],"path":"rules/windows/process_creation/proc_creation_win_rundll32_keymgr.yml","techniques":["T1555.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}