Windows Credential Editor (WCE) is a publicly available, dual-use Windows security utility from Amplia Security used to extract and reuse operating-system credentials. It superseded the original Pass-the-Hash Toolkit, extending its functionality and operating-system support. Although legitimate security practitioners can use WCE, adversaries employ it during post-exploitation to steal credentials, impersonate accounts, and expand access within Windows environments.
WCE extracts credentials and password hashes from Local Security Authority Subsystem Service (LSASS) memory. It supports pass-the-hash and pass-the-ticket operations, allowing authentication with acquired credential material without recovering the original plaintext password. These capabilities facilitate lateral movement and execution under higher-privileged accounts. Credential-access operations generally require local administrator privileges, and WCE can use remote-thread creation and module loading within LSASS during credential extraction.
Documented users include APT41, APT39, APT40, BRONZE BUTLER (Tick), Cleaver, FIN6, and FIN8. Its use spans espionage and financially motivated intrusions. Tick has deployed it during post-compromise operations against Japanese technology, engineering, and media organizations. WCE is principally a post-compromise tool rather than an initial-access payload and is not tied to a single infection vector or industry.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT41 has used hashdump, Mimikatz, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.
APT41 has used hashdump, Mimikatz, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.
APT41 has used hashdump, Mimikatz, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.
APT41 has used hashdump, Mimikatz, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.
APT41 has used hashdump, Mimikatz, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.
APT41 has used hashdump, Mimikatz, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
「192.168.1.x-PWHashes.txt」というファイルが一時的に作成された痕跡があったとします…この特徴的な「PWHashes.txt」という文字列で…PWDumpXを実行した際に作成されるファイルであることが分かります。…サーバー上のパスワードハッシュを入手する攻撃が実行されたと推測される
WCE (Remote Login) ... Remotely executes a command on another machine ... Windows Management Instrumentation ... WMIC.exe ... WmiPrvSE.exe ... random 5-digit port (WMIC)
WCE (Remote Login) pass-the-hash, pass-the-ticket ... Mimikatz (Remote Login) pass-the-hash, pass-the-ticket ... Executes a command with another user's privileges using a hash of the acquired password
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential dumping tool used to retrieve credentials from Windows systems, including LSASS-related extraction techniques; leaves service, file, and named pipe artifacts.
A credential theft/post-exploitation tool referenced as part of the broader discussion of techniques used in Active Directory compromise.
Dumps credentials and password hashes. The content also identifies its use by Daserf and Net Crawler.
Credential dumping tool used to extract credentials from Windows memory and local stores (e.g., SAM), including cached credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.