1200KM / tag
attack.credential-access — sigma-tag tag
335 related reference pages for sigma-tag: attack.credential-access.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Access to Browser Login Data · sigma-rule
- Access To Crypto Currency Wallets By Uncommon Applications · sigma-rule
- Access To Potentially Sensitive Sysvol Files By Uncommon Applications · sigma-rule
- Access To Windows Credential History File By Uncommon Applications · sigma-rule
- Access To Windows DPAPI Master Keys By Uncommon Applications · sigma-rule
- Account Lockout · sigma-rule
- Active Directory Certificate Services Denied Certificate Enrollment Request · sigma-rule
- Active Directory Replication from Non Machine Account · sigma-rule
- Added Owner To Application · sigma-rule
- Anomalous Token · sigma-rule
- Anonymous IP Address · sigma-rule
- Antivirus Password Dumper Detection · sigma-rule
- App Granted Microsoft Permissions · sigma-rule
- Application AppID Uri Configuration Changes · sigma-rule
- Application URI Configuration Changes · sigma-rule
- Attempts of Kerberos Coercion Via DNS SPN Spoofing · sigma-rule
- Audit CVE Event · sigma-rule
- Automated Collection Command Prompt · sigma-rule
- AWS ConsoleLogin Failed Authentication · sigma-rule
- AWS Identity Center Identity Provider Change · sigma-rule
- AWS Route 53 Domain Transfer Lock Disabled · sigma-rule
- AWS Route 53 Domain Transferred to Another Account · sigma-rule
- Azure AD Only Single Factor Authentication Required · sigma-rule
- Azure Key Vault Modified or Deleted · sigma-rule
- Azure Keyvault Key Modified or Deleted · sigma-rule
- Azure Keyvault Secrets Modified or Deleted · sigma-rule
- Azure Kubernetes Admission Controller · sigma-rule
- Azure Kubernetes Network Policy Change · sigma-rule
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted · sigma-rule
- Bitbucket User Login Failure · sigma-rule
- Bitbucket User Login Failure Via SSH · sigma-rule
- Browser Started with Remote Debugging · sigma-rule
- CA Policy Removed by Non Approved Actor · sigma-rule
- CA Policy Updated by Non Approved Actor · sigma-rule
- Capture Credentials with Rpcping.exe · sigma-rule
- Certificate Exported From Local Certificate Store · sigma-rule
- Certificate Exported Via PowerShell · sigma-rule
- Certificate Exported Via PowerShell - ScriptBlock · sigma-rule
- Certificate Private Key Acquired · sigma-rule
- Certificate-Based Authentication Enabled · sigma-rule
- Change to Authentication Method · sigma-rule
- Cisco BGP Authentication Failures · sigma-rule
- Cisco Collect Data · sigma-rule
- Cisco Crypto Commands · sigma-rule
- Cisco Dot1x Disabled · sigma-rule
- Cisco LDP Authentication Failures · sigma-rule
- Cisco Show Commands Input · sigma-rule
- Cisco Sniffing · sigma-rule
- Copy Passwd Or Shadow From TMP Path · sigma-rule
- Copying Sensitive Files with Credential Data · sigma-rule
- Crash Dump Created By Operating System · sigma-rule
- Create Volume Shadow Copy with Powershell · sigma-rule
- CreateDump Process Dump · sigma-rule
- Cred Dump Tools Dropped Files · sigma-rule
- Credential Dumping Activity By Python Based Tool · sigma-rule
- Credential Dumping Attempt Via WerFault · sigma-rule
- Credential Dumping Tools Service Execution - Security · sigma-rule
- Credential Dumping Tools Service Execution - System · sigma-rule
- Credential Manager Access By Uncommon Applications · sigma-rule
- Credentials from Password Stores - Keychain · sigma-rule
- Credentials In Files · sigma-rule
- Credentials In Files - Linux · sigma-rule
- CredUI.DLL Loaded By Uncommon Process · sigma-rule
- Critical Hive In Suspicious Location Access Bits Cleared · sigma-rule
- Delegated Permissions Granted For All Users · sigma-rule
- Directory Service Restore Mode(DSRM) Registry Value Tampering · sigma-rule
- Disabled MFA to Bypass Authentication Mechanisms · sigma-rule
- Disabling Multi Factor Authentication · sigma-rule
- DNS Query Request To OneLaunch Update Service · sigma-rule
- DPAPI Backup Keys And Certificate Export Activity IOC · sigma-rule
- DPAPI Domain Backup Key Extraction · sigma-rule
- DPAPI Domain Master Key Backup Attempt · sigma-rule
- Dropping Of Password Filter DLL · sigma-rule
- Dump Credentials from Windows Credential Manager With PowerShell · sigma-rule
- Dumping of Sensitive Hives Via Reg.EXE · sigma-rule
- Dumping Process via Sqldumper.exe · sigma-rule
- DumpMinitool Execution · sigma-rule
- End User Consent · sigma-rule
- End User Consent Blocked · sigma-rule
- Enumerate Credentials from Windows Credential Manager With PowerShell · sigma-rule
- Enumeration for 3rd Party Creds From CLI · sigma-rule
- Enumeration for Credentials in Registry · sigma-rule
- Esentutl Gather Credentials · sigma-rule
- Esentutl Volume Shadow Copy Service Keys · sigma-rule
- External Remote RDP Logon from Public IP · sigma-rule
- External Remote SMB Logon from Public IP · sigma-rule
- Extracting Information with PowerShell · sigma-rule
- Failed Authentications From Countries You Do Not Operate Out Of · sigma-rule
- File Access Of Signal Desktop Sensitive Data · sigma-rule
- Findstr GPP Passwords · sigma-rule
- Github High Risk Configuration Disabled · sigma-rule
- Google Cloud Kubernetes Admission Controller · sigma-rule
- Guacamole Two Users Sharing Session Anomaly · sigma-rule
- GUI Input Capture - macOS · sigma-rule
- Hack Tool User Agent · sigma-rule
- HackTool - ADCSPwn Execution · sigma-rule
- HackTool - Certify Execution · sigma-rule
- HackTool - Certipy Execution · sigma-rule
- HackTool - CrackMapExec Execution · sigma-rule
- HackTool - CrackMapExec File Indicators · sigma-rule
- HackTool - CrackMapExec Process Patterns · sigma-rule
- HackTool - CreateMiniDump Execution · sigma-rule
- HackTool - Credential Dumping Tools Named Pipe Created · sigma-rule
- HackTool - Doppelanger LSASS Dumper Execution · sigma-rule
- HackTool - Dumpert Process Dumper Default File · sigma-rule
- HackTool - Dumpert Process Dumper Execution · sigma-rule
- HackTool - Generic Process Access · sigma-rule
- HackTool - HandleKatz Duplicating LSASS Handle · sigma-rule
- HackTool - HandleKatz LSASS Dumper Execution · sigma-rule
- HackTool - Hashcat Password Cracker Execution · sigma-rule
- HackTool - Hydra Password Bruteforce Execution · sigma-rule
- HackTool - Impacket File Indicators · sigma-rule
- HackTool - Impacket Tools Execution · sigma-rule
- HackTool - Inveigh Execution · sigma-rule
- HackTool - Koh Default Named Pipe · sigma-rule
- HackTool - KrbRelay Execution · sigma-rule
- HackTool - KrbRelayUp Execution · sigma-rule
- HackTool - Mimikatz Execution · sigma-rule
- HackTool - Mimikatz Kirbi File Creation · sigma-rule
- HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump · sigma-rule
- HackTool - Pypykatz Credentials Dumping Activity · sigma-rule
- HackTool - Quarks PwDump Execution · sigma-rule
- HackTool - QuarksPwDump Dump File · sigma-rule
- HackTool - RemoteKrbRelay Execution · sigma-rule
- HackTool - Rubeus Execution · sigma-rule
- HackTool - Rubeus Execution - ScriptBlock · sigma-rule
- HackTool - SafetyKatz Dump Indicator · sigma-rule
- HackTool - SafetyKatz Execution · sigma-rule
- HackTool - SecurityXploded Execution · sigma-rule
- HackTool - Typical HiveNightmare SAM File Export · sigma-rule
- HackTool - Windows Credential Editor (WCE) Execution · sigma-rule
- HackTool - WinPwn Execution · sigma-rule
- HackTool - WinPwn Execution - ScriptBlock · sigma-rule
- HackTool - WSASS Execution · sigma-rule
- HackTool - XORDump Execution · sigma-rule
- Hacktool Execution - Imphash · sigma-rule
- Hacktool Execution - PE Metadata · sigma-rule
- Harvesting Of Wifi Credentials Via Netsh.EXE · sigma-rule
- Hidden Flag Set On File/Directory Via Chflags - MacOS · sigma-rule
- Huawei BGP Authentication Failures · sigma-rule
- Insensitive Subfolder Search Via Findstr.EXE · sigma-rule
- Interesting Service Enumeration Via Sc.EXE · sigma-rule
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) · sigma-rule
- ISATAP Router Address Was Set · sigma-rule
- Juniper BGP Missing MD5 · sigma-rule
- Kerberoasting Activity - Initial Query · sigma-rule
- Kerberos Manipulation · sigma-rule
- Kerberos Network Traffic RC4 Ticket Encryption · sigma-rule
- Kubernetes Admission Controller Modification · sigma-rule
- Kubernetes Secrets Enumeration · sigma-rule
- Linux Keylogging with Pam.d · sigma-rule
- Linux Recon Indicators · sigma-rule
- Live Memory Dump Using Powershell · sigma-rule
- Loaded Module Enumeration Via Tasklist.EXE · sigma-rule
- Local Privilege Escalation Indicator TabTip · sigma-rule
- LSASS Access Detected via Attack Surface Reduction · sigma-rule
- LSASS Access From Non System Account · sigma-rule
- LSASS Access From Potentially White-Listed Processes · sigma-rule
- LSASS Dump Keyword In CommandLine · sigma-rule
- Lsass Full Dump Request Via DumpType Registry Settings · sigma-rule
- LSASS Memory Access by Tool With Dump Keyword In Name · sigma-rule
- Lsass Memory Dump via Comsvcs DLL · sigma-rule
- LSASS Process Crashed - Application · sigma-rule
- LSASS Process Dump Artefact In CrashDumps Folder · sigma-rule
- LSASS Process Memory Dump Creation Via Taskmgr.EXE · sigma-rule
- LSASS Process Memory Dump Files · sigma-rule
- LSASS Process Reconnaissance Via Findstr.EXE · sigma-rule
- Microsoft IIS Connection Strings Decryption · sigma-rule
- Microsoft IIS Service Account Password Dumped · sigma-rule
- Microsoft Teams Sensitive File Access By Uncommon Applications · sigma-rule
- Mimikatz DC Sync · sigma-rule
- Mimikatz Use · sigma-rule
- Mount Execution With Hidepid Parameter · sigma-rule
- MSSQL Server Failed Logon · sigma-rule
- MSSQL Server Failed Logon From External Network · sigma-rule
- Multifactor Authentication Denied · sigma-rule
- Multifactor Authentication Interrupted · sigma-rule
- Network Sniffing - Linux · sigma-rule
- Network Sniffing - MacOs · sigma-rule
- New Generic Credentials Added Via Cmdkey.EXE · sigma-rule
- New Network Trace Capture Started Via Netsh.EXE · sigma-rule
- New Root Certificate Authority Added · sigma-rule
- No Suitable Encryption Key Found For Generating Kerberos Ticket · sigma-rule
- Notepad++ Updater DNS Query to Uncommon Domains · sigma-rule
- NTDS Exfiltration Filename Patterns · sigma-rule
- NTDS.DIT Created · sigma-rule
- NTDS.DIT Creation By Uncommon Parent Process · sigma-rule
- NTDS.DIT Creation By Uncommon Process · sigma-rule
- Ntdsutil Abuse · sigma-rule
- NTLM Brute Force · sigma-rule
- NTLM Hash Leak Via Curl NTLM Authentication · sigma-rule
- Okta MFA Reset or Deactivated · sigma-rule
- OpenCanary - MSSQL Login Attempt Via SQLAuth · sigma-rule
- OpenCanary - MSSQL Login Attempt Via Windows Authentication · sigma-rule
- OpenCanary - MySQL Login Attempt · sigma-rule
- OpenCanary - REDIS Action Command Attempt · sigma-rule
- Password Dumper Activity on LSASS · sigma-rule
- Password Dumper Remote Thread in LSASS · sigma-rule
- Password Reset By User Account · sigma-rule
- Password Spray Activity · sigma-rule
- Permission Misconfiguration Reconnaissance Via Findstr.EXE · sigma-rule
- PetitPotam Suspicious Kerberos TGT Request · sigma-rule
- PktMon.EXE Execution · sigma-rule
- Possible DC Shadow Attack · sigma-rule
- Possible Impacket SecretDump Remote Activity · sigma-rule
- Possible Impacket SecretDump Remote Activity - Zeek · sigma-rule
- Possible PetitPotam Coerce Authentication Attempt · sigma-rule
- Possible Shadow Credentials Added · sigma-rule
- Potential Adplus.EXE Abuse · sigma-rule
- Potential Browser Data Stealing · sigma-rule
- Potential Credential Dumping Activity Via LSASS · sigma-rule
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI · sigma-rule
- Potential Credential Dumping Attempt Using New NetworkProvider - REG · sigma-rule
- Potential Credential Dumping Attempt Via PowerShell Remote Thread · sigma-rule
- Potential Credential Dumping Via LSASS Process Clone · sigma-rule
- Potential Credential Dumping Via LSASS SilentProcessExit Technique · sigma-rule
- Potential Credential Dumping Via WER · sigma-rule
- Potential Data Stealing Via Chromium Headless Debugging · sigma-rule
- Potential Invoke-Mimikatz PowerShell Script · sigma-rule
- Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation · sigma-rule
- Potential Keylogger Activity · sigma-rule
- Potential LSASS Process Dump Via Procdump · sigma-rule
- Potential MFA Bypass Using Legacy Client Authentication · sigma-rule
- Potential Network Sniffing Activity Using Network Tools · sigma-rule
- Potential Okta Password in AlternateID Field · sigma-rule
- Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock · sigma-rule
- Potential PetitPotam Attack Via EFS RPC Calls · sigma-rule
- Potential PowerShell Console History Access Attempt via History File · sigma-rule
- Potential Privilege Escalation via Local Kerberos Relay over LDAP · sigma-rule
- Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE · sigma-rule
- Potential SAM Database Dump · sigma-rule
- Potential SMB Relay Attack Tool Execution · sigma-rule
- Potential SPN Enumeration Via Setspn.EXE · sigma-rule
- Potential Suspicious Activity Using SeCEdit · sigma-rule
- Potential SysInternals ProcDump Evasion · sigma-rule
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock · sigma-rule
- Potential Windows Defender AV Bypass Via Dump64.EXE Rename · sigma-rule
- Potentially Suspicious AccessMask Requested From LSASS · sigma-rule
- Potentially Suspicious Command Targeting Teams Sensitive Files · sigma-rule
- Potentially Suspicious EventLog Recon Activity Using Log Query Utilities · sigma-rule
- Potentially Suspicious GrantedAccess Flags On LSASS · sigma-rule
- Potentially Suspicious JWT Token Search Via CLI · sigma-rule
- Potentially Suspicious ODBC Driver Registered · sigma-rule
- PowerShell Credential Prompt · sigma-rule
- PowerShell Get-Process LSASS · sigma-rule
- PowerShell Get-Process LSASS in ScriptBlock · sigma-rule
- Powershell Install a DLL in System Directory · sigma-rule
- Powershell Keylogging · sigma-rule
- PowerShell SAM Copy · sigma-rule
- PPL Tampering Via WerFaultSecure · sigma-rule
- Primary Refresh Token Access Attempt · sigma-rule
- Private Keys Reconnaissance Via CommandLine Tools · sigma-rule
- Procdump Execution · sigma-rule
- Process Access via TrolleyExpress Exclusion · sigma-rule
- Process Memory Dump Via Comsvcs.DLL · sigma-rule
- Process Memory Dump via RdrLeakDiag.EXE · sigma-rule
- PUA - AWS TruffleHog Execution · sigma-rule
- PUA - DIT Snapshot Viewer · sigma-rule
- PUA - Memory Dump Mount Via MemProcFS · sigma-rule
- PUA - Mouse Lock Execution · sigma-rule
- PUA - TruffleHog Execution · sigma-rule
- PUA - TruffleHog Execution - Linux · sigma-rule
- PUA - WebBrowserPassView Execution · sigma-rule
- Rare Subscription-level Operations In Azure · sigma-rule
- Register new Logon Process by Rubeus · sigma-rule
- Registry Export of Third-Party Credentials · sigma-rule
- Remote File Download Via Findstr.EXE · sigma-rule
- Remote LSASS Process Access Through Windows Remote Management · sigma-rule
- Remote Thread Created In KeePass.EXE · sigma-rule
- Renamed BrowserCore.EXE Execution · sigma-rule
- Renamed CreateDump Utility Execution · sigma-rule
- Replay Attack Detected · sigma-rule
- RottenPotato Like Attack Pattern · sigma-rule
- SAM Registry Hive Handle Request · sigma-rule
- SAML Token Issuer Anomaly · sigma-rule
- Script Interpreter Spawning Credential Scanner - Linux · sigma-rule
- Script Interpreter Spawning Credential Scanner - Windows · sigma-rule
- Sensitive File Dump Via Print.EXE · sigma-rule
- Sensitive File Dump Via Wbadmin.EXE · sigma-rule
- Sensitive File Recovery From Backup Via Wbadmin.EXE · sigma-rule
- Shadow Copies Creation Using Operating Systems Utilities · sigma-rule
- Sign-in Failure Due to Conditional Access Requirements Not Met · sigma-rule
- SQLite Chromium Profile Data DB Access · sigma-rule
- SQLite Firefox Profile Data DB Access · sigma-rule
- Successful Authentications From Countries You Do Not Operate Out Of · sigma-rule
- Suspicious Child Process of Notepad++ Updater - GUP.Exe · sigma-rule
- Suspicious Connection to Remote Account · sigma-rule
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing · sigma-rule
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network · sigma-rule
- Suspicious DumpMinitool Execution · sigma-rule
- Suspicious File Access to Browser Credential Storage · sigma-rule
- Suspicious Get-ADDBAccount Usage · sigma-rule
- Suspicious Get-ADReplAccount · sigma-rule
- Suspicious History File Operations · sigma-rule
- Suspicious History File Operations - Linux · sigma-rule
- Suspicious Kerberos RC4 Ticket Encryption · sigma-rule
- Suspicious Kerberos Ticket Request via CLI · sigma-rule
- Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock · sigma-rule
- Suspicious Key Manager Access · sigma-rule
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location · sigma-rule
- Suspicious LSASS Access Via MalSecLogon · sigma-rule
- Suspicious Network Communication With IPFS · sigma-rule
- Suspicious NTLM Authentication on the Printer Spooler Service · sigma-rule
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs · sigma-rule
- Suspicious Process Patterns NTDS.DIT Exfil · sigma-rule
- Suspicious Rejected SMB Guest Logon From IP · sigma-rule
- Suspicious Renamed Comsvcs DLL Loaded By Rundll32 · sigma-rule
- Suspicious Serv-U Process Pattern · sigma-rule
- Suspicious SYSTEM User Process Creation · sigma-rule
- Suspicious SYSVOL Domain Group Policy Access · sigma-rule
- Suspicious Teams Application Related ObjectAcess Event · sigma-rule
- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded · sigma-rule
- Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe) · sigma-rule
- Time Travel Debugging Utility Usage · sigma-rule
- Time Travel Debugging Utility Usage - Image · sigma-rule
- Transferring Files with Credential Data via Network Shares · sigma-rule
- Transferring Files with Credential Data via Network Shares - Zeek · sigma-rule
- Uncommon File Created by Notepad++ Updater Gup.EXE · sigma-rule
- Uncommon Outbound Kerberos Connection · sigma-rule
- Uncommon Outbound Kerberos Connection - Security · sigma-rule
- Unsigned Image Loaded Into LSASS Process · sigma-rule
- Use of Legacy Authentication Protocols · sigma-rule
- User Access Blocked by Azure Conditional Access · sigma-rule
- User Added To Group With CA Policy Modification Access · sigma-rule
- User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess' · sigma-rule
- User Removed From Group With CA Policy Modification Access · sigma-rule
- Volume Shadow Copy Mount · sigma-rule
- VolumeShadowCopy Symlink Creation Via Mklink · sigma-rule
- VSSAudit Security Event Source Registration · sigma-rule
- WCE wceaux.dll Access · sigma-rule
- WerFault LSASS Process Memory Dump · sigma-rule
- WinDivert Driver Load · sigma-rule
- Windows Credential Editor Registry · sigma-rule
- Windows Credential Manager Access via VaultCmd · sigma-rule
- Windows Pcap Drivers · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.