<<< Hide Navigation Hide TOC >>>
Enumeration for 3rd Party Creds From CLI (87a476dc-0079-4583-a985-dee7a20a03de)
Detects processes that query known 3rd party registry keys that holds credentials via commandline
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Enumeration for 3rd Party Creds From CLI (87a476dc-0079-4583-a985-dee7a20a03de) | Sigma-Rules | Credentials in Registry - T1552.002 (341e222a-a6e3-4f6f-b69c-831d792b1580) | Attack Pattern | 1 |
Credentials in Registry - T1552.002 (341e222a-a6e3-4f6f-b69c-831d792b1580) | Attack Pattern | Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) | Attack Pattern | 2 |