Credential Added to Public IPv4 Address via Cmdkey.EXE

Rule Info

Name
Credential Added to Public IPv4 Address via Cmdkey.EXE
Author
Swachchhanda Shrawan Poudel (Nextron Systems), Marius Benthin (Nextron Systems)
Description
Detects the addition of credentials to a public IPv4 address via cmdkey.exe. Adding credential to cmdkey allows attackers to store credentials for later use. Threat Actors may use this technique to access remote systems without being prompted for credentials and use automated scripts more effectively.
Date
2026-07-05 00:00:00
Modified
None
Id
c29f4813-774d-40e4-b79c-fd2de305a3f9
Tags
attack.credential-access attack.t1555.004
Type
Nextron Sigma feed only (private)

Rule History