Credential Manager access via known tools

Detects access to the Windows Credential Manager using built-in utilities such as vaultcmd.exe, cmdkey.exe, rundll32.exe, and control.exe. Adversaries can abuse these native tools to enumerate or interact with stored credentials.

Back to all rules