{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/security-auditing/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["medium"],"_cs_tags":["windows","security-auditing","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief details a detection engineering approach for identifying suspicious use of explicit credentials within a Windows environment. Windows Event ID 4648 is generated when a process attempts to log on to a local or remote resource using explicit credentials, such as when using the 'runas' command. While this is a legitimate administrative function, attackers frequently leverage this technique to escalate privileges or move laterally after harvesting credentials from memory or local configuration files. This rule specifically targets local logon attempts where the process executing the request originates from non-standard directories and does not match the current user context, effectively filtering out common system-managed or administrative activity to highlight potential abuse.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of explicit credentials allows an attacker to bypass standard access controls, impersonate other users (including high-privilege service accounts or domain administrators), and maintain persistence within the target system. This technique is often a critical stage in the progression from initial access to full domain compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDeploy the provided Sigma rule to your SIEM environment to detect deviations from established administrative patterns.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable Windows Security Auditing (specifically \u0026quot;Audit Logon\u0026quot; subcategory) to ensure Event ID 4648 is generated.\u003c/li\u003e\n\u003cli\u003eBaseline common administrative tools used in the environment to tune the 'filter_main_*' selections and minimize false positives.\u003c/li\u003e\n\u003cli\u003eAlert on occurrences that bypass current filters, as these represent high-interest activity for manual threat hunting.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T08:54:29Z","date_published":"2026-08-03T08:54:29Z","id":"https://feed.craftedsignal.io/briefs/2026-08-explicit-credential-logon/","summary":"Detection logic for monitoring Windows Event ID 4648 to identify potential privilege escalation through unauthorized explicit credential usage.","title":"Detection of Suspicious Explicit Credential Local Logon","url":"https://feed.craftedsignal.io/briefs/2026-08-explicit-credential-logon/"}],"language":"en","title":"CraftedSignal Threat Feed - Security-Auditing","version":"https://jsonfeed.org/version/1.1"}