Skip to content

<<< Hide Navigation Hide TOC >>>

Enumeration for 3rd Party Creds From CLI (87a476dc-0079-4583-a985-dee7a20a03de)

Detects processes that query known 3rd party registry keys that holds credentials via commandline

Galaxy ColorsSigma-Rule...Attack Pat...
Rows: 2
Loading extensions...
Collapse filters
Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
<, <=, >, >=, =, *, !, {, }, ||,&&, [empty], [nonempty], rgx:
Learn more

TableFilter v0.7.2

https://www.tablefilter.com/
©2015-2025 Max Guglielmi
?
Cluster A Galaxy A Cluster B Galaxy B Level
Enumeration for 3rd Party Creds From CLI (87a476dc-0079-4583-a985-dee7a20a03de) Sigma-Rules Credentials in Registry - T1552.002 (341e222a-a6e3-4f6f-b69c-831d792b1580) Attack Pattern 1
Credentials in Registry - T1552.002 (341e222a-a6e3-4f6f-b69c-831d792b1580) Attack Pattern Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) Attack Pattern 2