Analytics BIOC Low

Cached credentials discovery with cmdkey

Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006) Discovery (TA0007)
ATT&CK techniques: OS Credential Dumping (T1003) Account Discovery (T1087)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:

Access cached user credentials.

Investigative actions:

Check the initiator process for additional suspicious activity. Check if the host is a shared host that multiple users' credentials can be extracted from.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • The process cmdkey runs with modified name and extract cached credentials High (parent: Low)
  • Transfer cached credentials with cmdkey to other standard output Medium (parent: Low)