PowerShell P/Invoke Of CredEnumerate For Credential Manager Extraction
Detects PowerShell script block telemetry (Event ID 4104) containing P/Invoke declarations targeting advapi32.dll's CredEnumerate function or related Credential Manager APIs (CredRead, CredWrite). This technique bypasses standard cmdlets that may be monitored or restricted, providing direct API access to stored Windows credentials including RDP sessions, web service credentials, and enterprise application tokens. Generalizes well beyond specific campaigns to most PowerShell credential-theft families.
Cortex XDR

