Enumeration for 3rd Party Creds From CLI

 Original Source: [Sigma source]
Title: Enumeration for 3rd Party Creds From CLI
Status: test
Description:Detects processes that query known 3rd party registry keys that holds credentials via commandline
References:
  -https://isc.sans.edu/diary/More+Data+Exfiltration/25698
  -https://github.com/synacktiv/Radmin3-Password-Cracker/blob/acfc87393e4b7c06353973a14a6c7126a51f36ac/regkey.txt
  -https://github.com/HyperSine/how-does-MobaXterm-encrypt-password
  -https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#inside-the-registry
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-20
modified:2025-05-22
Tags:
  • -'attack.credential-access'
  • -'attack.t1552.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'\Software\Aerofox\Foxmail\V3.1'
      -'\Software\Aerofox\FoxmailPreview'
      -'\Software\DownloadManager\Passwords'
      -'\Software\FTPWare\COREFTP\Sites'
      -'\Software\IncrediMail\Identities'
      -'\Software\Martin Prikryl\WinSCP 2\Sessions'
      -'\Software\Mobatek\MobaXterm\'
      -'\Software\OpenSSH\Agent\Keys'
      -'\Software\OpenVPN-GUI\configs'
      -'\Software\ORL\WinVNC3\Password'
      -'\Software\Qualcomm\Eudora\CommandLine'
      -'\Software\RealVNC\WinVNC4'
      -'\Software\RimArts\B2\Settings'
      -'\Software\SimonTatham\PuTTY\Sessions'
      -'\Software\SimonTatham\PuTTY\SshHostKeys\'
      -'\Software\Sota\FFFTP'
      -'\Software\TightVNC\Server'
      -'\Software\WOW6432Node\Radmin\v3.0\Server\Parameters\Radmin'

  filter_main_other_rule:
    Image|endswith: 'reg.exe'
    CommandLine|contains:
      -'export'
      -'save'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium