KuinaExtractor-Style Windows Credential Manager Dump via vaultcmd/cmdkey/PowerShell Vault
Detects adversary activity consistent with credential dumping tools like KuinaExtractor. The rule monitors for the enumeration of Windows Credential Manager stores using vaultcmd /list or cmdkey /list, and the direct instantiation of the Windows PasswordVault via PowerShell, excluding system accounts and known legitimate applications.
Microsoft Sentinel (KQL)

