Windows Credential Manager Access via cmdkey, vaultcmd, or PowerShell Get-StoredCredential
Detects unauthorized attempts to access or list stored credentials via Windows Credential Manager using standard administrative tools (cmdkey.exe, vaultcmd.exe) or PowerShell, as well as direct unauthorized access to credential storage files within the AppData directory.
SentinelOne

