โ† Library
sigmaDRL-1.1from SigmaHQ/sigma

HackTool - Windows Credential Editor (WCE) Execution

Detects the use of Windows Credential Editor (WCE), a popular post-exploitation tool used to extract plaintext passwords, hash, PIN code and Kerberos tickets from memory. It is often used by threat actors for credential dumping and lateral movement within compromised networks.

Quality
84
FP risk
โ€”
Forks
0
Views
1
ATT&CK techniques
Rule source๐Ÿ”’ locked
๐Ÿ”’

Sign in to view the rule source

Free accounts can view the source for the top-ranked rules. Create one in seconds โ€” no credit card required.

Sign in โ†’
HackTool - Windows Credential Editor (WCE) Execution ยท SIGMA rule | DetectionLint