Windows Credential Editor (WCE) is a publicly available Windows post-exploitation credential theft utility used to extract authentication material from compromised systems. It is primarily associated with dumping credentials from LSASS memory and local credential stores, including password hashes and other reusable authentication data, and has also been used to support pass-the-hash and pass-the-ticket style operations. The tool generally requires local administrator privileges and is typically deployed after initial compromise to expand access, impersonate users, and facilitate lateral movement within Windows domains.
WCE has been widely referenced alongside tools such as Mimikatz, ProcDump, and pwdump variants in intrusion activity. It has been used by multiple threat actors, including APT39, APT40, APT41, FIN6, FIN8, and other espionage and criminal operators, particularly during credential dumping and privilege escalation phases. Reporting also links it to remote execution workflows in which stolen hashes are reused to authenticate and execute commands on other systems.
The tool targets Windows environments and is most commonly discussed in enterprise Active Directory contexts where credentials present in memory can enable compromise of additional hosts or privileged accounts. Its operational role is best characterized as credential access and post-exploitation rather than initial access. Because it is a dual-use security tool, malicious use is often distinguished by context such as unauthorized LSASS access, credential dumping activity, and subsequent lateral movement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.
APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.
APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.
APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.
APT41 has obtained and used tools such as Mimikatz, pwdump, PowerSploit, and Windows Credential Editor.
Tools: Mimikatz, Invoke-Mimikatz, Windows Credential Editor (WCE), fgdump, pwdump6, pwdumpX
12 distinct techniques documented for this family, organized by ATT&CK tactic.
「192.168.1.x-PWHashes.txt」というファイルが一時的に作成された痕跡があったとします…この特徴的な「PWHashes.txt」という文字列で…PWDumpXを実行した際に作成されるファイルであることが分かります。…サーバー上のパスワードハッシュを入手する攻撃が実行されたと推測される
WCE (Remote Login) ... Remotely executes a command on another machine ... Windows Management Instrumentation ... WMIC.exe ... WmiPrvSE.exe ... random 5-digit port (WMIC)
WCE (Remote Login) pass-the-hash, pass-the-ticket ... Mimikatz (Remote Login) pass-the-hash, pass-the-ticket ... Executes a command with another user's privileges using a hash of the acquired password
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential dumping tool used to retrieve credentials from Windows systems, including LSASS-related extraction techniques; leaves service, file, and named pipe artifacts.
A credential theft/post-exploitation tool referenced as part of the broader discussion of techniques used in Active Directory compromise.
Credential dumping tool used to extract credentials from Windows memory and local stores (e.g., SAM), including cached credentials.
Credential theft utility included in the attacker toolkit to capture credentials in enterprise environments, supporting privilege escalation and ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.