Analytics BIOC
Low
✕
Cached credentials discovery with cmdkey
Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Credential Access (TA0006) Discovery (TA0007)
ATT&CK techniques: OS Credential Dumping (T1003) Account Discovery (T1087)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:
Access cached user credentials.
Investigative actions:
Check the initiator process for additional suspicious activity. Check if the host is a shared host that multiple users' credentials can be extracted from.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- The process cmdkey runs with modified name and extract cached credentials High (parent: Low)
- Transfer cached credentials with cmdkey to other standard output Medium (parent: Low)