Windows Credential Editor

MITRE ATT&CK: S0005 View on attack.mitre.org

Aliases: WCE, Windows Credential Editor

First seen
2010-01-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:32:00

Context

Windows Credential Editor is a password dumping tool.

Detection coverage

  • 73 Sigma rules

Malware & tools used

  • LSASS Memory (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0005 (report)
  • web.archive.org — Wcefaq (report)

External references