WDigest UseLogonCredential toggled then reverted (hit-and-run)
Detects the temporary enablement of the UseLogonCredential registry value by setting it to 1, followed by a subsequent reversion to 0 on the same host. This pattern is indicative of a deliberate 'hit-and-run' attempt to force the WDigest security package to store plaintext credentials in memory for harvesting.
YARA-L

