Windows Credential Manager Enumeration via vaultcmd, cmdkey, or PowerShell
Detects unauthorized attempts to enumerate stored Windows credentials using native command-line utilities such as vaultcmd.exe and cmdkey.exe, or by invoking CredEnumerate/Get-StoredCredential functions via PowerShell scripts. These methods are commonly used by attackers to gain access to cached passwords, tokens, or network credentials stored in the Windows Credential Manager.
SentinelOne

