Potentially Suspicious Explicit Credential Local Logon


Description

Detects potentially suspicious explicit credential logon events where the user is trying to logon with explicit credentials (username and password) that are different from the current user context. It might indicate an attacker attempting to escalate privileges after obtaining credentials for a different user account.

Query · sigma

selection_eid:
  EventID: 4648
selection_localhost:
- TargetServerName: localhost
- TargetInfo: localhost
- IpAddress:
  - 127.0.0.1
  - ::1
filter_main_computer_accounts:
  SubjectUserName|endswith: $
filter_main_system_processes:
  ProcessName|startswith:
  - C:\Windows\System32\
  - C:\Windows\SysWOW64\
  - C:\Windows\WinSxS\
filter_main_program_files:
  ProcessName|startswith:
  - C:\Program Files\
  - C:\Program Files (x86)\
filter_main_same_user:
  SubjectUserName|fieldref: TargetUserName
condition: all of selection_* and not 1 of filter_main_*

Known false positives

  • RunAs usage from user-installed applications outside Program Files
  • Administrative scripts using explicit credentials from non-standard paths
Raw source Potentially Suspicious Explicit Credential Local Logon · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Potentially Suspicious Explicit Credential Local Logon
id: e3c6d245-7b8f-4e2a-c17f-a9d0e5b38f62
status: experimental
description: |
    Detects potentially suspicious explicit credential logon events where the user
    is trying to logon with explicit credentials (username and password) that are
    different from the current user context. It might indicate an attacker attempting
    to escalate privileges after obtaining credentials for a different user account.
references:
    - https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648
    - https://github.com/MSNightmare/LegacyHive
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2026-07-23
tags:
    - attack.privilege-escalation
    - attack.stealth
    - attack.t1134
    - attack.t1134.003
logsource:
    product: windows
    service: security
detection:
    selection_eid:
        EventID: 4648
    selection_localhost:
        - TargetServerName: 'localhost'
        - TargetInfo: 'localhost'
        - IpAddress:
              - '127.0.0.1'
              - '::1'
    filter_main_computer_accounts:
        SubjectUserName|endswith: '$'
    filter_main_system_processes:
        ProcessName|startswith:
            - 'C:\Windows\System32\'
            - 'C:\Windows\SysWOW64\'
            - 'C:\Windows\WinSxS\'
    filter_main_program_files:
        ProcessName|startswith:
            - 'C:\Program Files\'
            - 'C:\Program Files (x86)\'
    filter_main_same_user:
        SubjectUserName|fieldref: TargetUserName
    condition: all of selection_* and not 1 of filter_main_*
falsepositives:
    - RunAs usage from user-installed applications outside Program Files
    - Administrative scripts using explicit credentials from non-standard paths
level: medium
regression_tests_path: regression_data/rules/windows/builtin/security/win_security_explicit_credential_local_logon/info.yml

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.