Potential Discovery of DPAPI Master Keys


Description

Identifies an unusual process accessing Data Protection API Master keys. Adversaries may attempt to discover and acquire credentials from the Windows Credential Manager.

Query · eql

file where event.action == "open" and
 file.path : ("?:\\USERS\\*\\APPDATA\\*\\MICROSOFT\\PROTECT\\S-1-5-21*\\*",
              "?:\\USERS\\*\\APPDATA\\*\\MICROSOFT\\PROTECT\\S-1-12-1-*\\*",
              "?:\\WINDOWS\\SYSTEM32\\MICROSOFT\\PROTECT\\S-1-5-18\\USER\\*") and
 process.executable : ("C:\\*", "\\Device\\Mup\\*") and
 user.id like ("S-1-5-21*", "S-1-12-*") and
 not file.name : ("desktop.ini", "exclude", ".fdignore", ".rgignore", ".ignore", ".gitignore") and
 not process.executable :
           ("?:\\Program Files\\*",
            "?:\\Program Files (x86)\\*",
            "?:\\Windows\\System32\\lsass.exe",
            "?:\\Windows\\System32\\svchost.exe",
            "?:\\Windows\\System32\\Robocopy.exe",
            "System",
            "?:\\Windows\\ccmcache\\*.exe",
            "?:\\WINDOWS\\CCM\\*.exe",
            "?:\\Windows\\SysWOW64\\prevhost.exe",
            "?:\\Windows\\System32\\prevhost.exe",
            "?:\\Veritas\\NetBackup\\bin\\bpbkar32.exe",
            "?:\\Windows\\System32\\taskhostw.exe",
            "?:\\Windows\\System32\\taskhost.exe",
            "?:\\Windows\\System32\\sdiagnhost.exe",
            "?:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
            "?:\\$WINDOWS.~BT\\Sources\\setuphost.exe",
            "?:\\Windows\\explorer.exe",
            "?:\\Windows\\System32\\sppsvc.exe",
            "?:\\Windows\\System32\\backgroundTaskHost.exe",
            "?:\\Windows\\System32\\dllhost.exe",
            "?:\\Windows\\WID\\Binn\\sqlservr.exe",
            "?:\\Windows\\System32\\SearchProtocolHost.exe",
            "?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\*.exe",
            "?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
            "?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
            "?:\\Program Files\\Windows Defender Advanced Threat Protection\\*.exe",
            "?:\\Windows\\System32\\igfxtray.exe",
            "?:\\$WINDOWS.~BT\\Sources\\SetupCore.exe",
            "?:\\Windows\\System32\\pacjsworker.exe",
            "?:\\Windows\\System32\\MoUsoCoreWorker.exe",
            "?:\\Windows\\System32\\conhost.exe",
            "?:\\Windows\\System32\\LocationNotificationWindows.exe",
            "?:\\Windows\\System32\\MRT.exe",
            "?:\\Windows\\twain_32\\Brimc16a\\Common\\TwDsUiLaunch.exe",
            "?:\\Windows\\Microsoft.NET\\Framework64\\*\\csc.exe",
            "?:\\Users\\*\\AppData\\Local\\JetBrains\\Toolbox\\apps\\datagrip\\ch-0\\203.5981.102\\bin\\datagrip64.exe",
            "?:\\Windows\\cybercnsagent\\osqueryi.exe") and
 /* MSSQL service account */
 not (process.name : "sqlservr.exe" and file.path : "?:\\Users\\svc_*") and
 not (process.name : ("MicrosoftEdgeUpdate.exe", "Teams.exe") and
      process.code_signature.subject_name : "Microsoft Corporation" and process.code_signature.trusted == true) and
 not (process.code_signature.subject_name : ("ESET, spol. s r.o.", "Intel(R) pGFX", "ForensiT Limited", "Johannes Schindelin") and
      process.code_signature.trusted == true) and
 not (process.name : "r-LiteCollector.exe" and process.code_signature.status : "errorCode_endpoint*")
Raw source Potential Discovery of DPAPI Master Keys · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Identifies an unusual process accessing Data Protection API Master keys. Adversaries may attempt to discover and acquire
credentials from the Windows Credential Manager.
"""
id = "84bbe951-5141-4eb3-b9cf-8dfeea62a94e"
license = "Elastic License v2"
name = "Potential Discovery of DPAPI Master Keys"
os_list = ["windows"]
reference = ["http://www.harmj0y.net/blog/redteaming/operational-guidance-for-offensive-user-dpapi-abuse/"]
version = "1.0.38"

query = '''
file where event.action == "open" and
 file.path : ("?:\\USERS\\*\\APPDATA\\*\\MICROSOFT\\PROTECT\\S-1-5-21*\\*",
              "?:\\USERS\\*\\APPDATA\\*\\MICROSOFT\\PROTECT\\S-1-12-1-*\\*",
              "?:\\WINDOWS\\SYSTEM32\\MICROSOFT\\PROTECT\\S-1-5-18\\USER\\*") and
 process.executable : ("C:\\*", "\\Device\\Mup\\*") and
 user.id like ("S-1-5-21*", "S-1-12-*") and
 not file.name : ("desktop.ini", "exclude", ".fdignore", ".rgignore", ".ignore", ".gitignore") and
 not process.executable :
           ("?:\\Program Files\\*",
            "?:\\Program Files (x86)\\*",
            "?:\\Windows\\System32\\lsass.exe",
            "?:\\Windows\\System32\\svchost.exe",
            "?:\\Windows\\System32\\Robocopy.exe",
            "System",
            "?:\\Windows\\ccmcache\\*.exe",
            "?:\\WINDOWS\\CCM\\*.exe",
            "?:\\Windows\\SysWOW64\\prevhost.exe",
            "?:\\Windows\\System32\\prevhost.exe",
            "?:\\Veritas\\NetBackup\\bin\\bpbkar32.exe",
            "?:\\Windows\\System32\\taskhostw.exe",
            "?:\\Windows\\System32\\taskhost.exe",
            "?:\\Windows\\System32\\sdiagnhost.exe",
            "?:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
            "?:\\$WINDOWS.~BT\\Sources\\setuphost.exe",
            "?:\\Windows\\explorer.exe",
            "?:\\Windows\\System32\\sppsvc.exe",
            "?:\\Windows\\System32\\backgroundTaskHost.exe",
            "?:\\Windows\\System32\\dllhost.exe",
            "?:\\Windows\\WID\\Binn\\sqlservr.exe",
            "?:\\Windows\\System32\\SearchProtocolHost.exe",
            "?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\*.exe",
            "?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
            "?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
            "?:\\Program Files\\Windows Defender Advanced Threat Protection\\*.exe",
            "?:\\Windows\\System32\\igfxtray.exe",
            "?:\\$WINDOWS.~BT\\Sources\\SetupCore.exe",
            "?:\\Windows\\System32\\pacjsworker.exe",
            "?:\\Windows\\System32\\MoUsoCoreWorker.exe",
            "?:\\Windows\\System32\\conhost.exe",
            "?:\\Windows\\System32\\LocationNotificationWindows.exe",
            "?:\\Windows\\System32\\MRT.exe",
            "?:\\Windows\\twain_32\\Brimc16a\\Common\\TwDsUiLaunch.exe",
            "?:\\Windows\\Microsoft.NET\\Framework64\\*\\csc.exe",
            "?:\\Users\\*\\AppData\\Local\\JetBrains\\Toolbox\\apps\\datagrip\\ch-0\\203.5981.102\\bin\\datagrip64.exe",
            "?:\\Windows\\cybercnsagent\\osqueryi.exe") and
 /* MSSQL service account */
 not (process.name : "sqlservr.exe" and file.path : "?:\\Users\\svc_*") and
 not (process.name : ("MicrosoftEdgeUpdate.exe", "Teams.exe") and
      process.code_signature.subject_name : "Microsoft Corporation" and process.code_signature.trusted == true) and
 not (process.code_signature.subject_name : ("ESET, spol. s r.o.", "Intel(R) pGFX", "ForensiT Limited", "Johannes Schindelin") and
      process.code_signature.trusted == true) and
 not (process.name : "r-LiteCollector.exe" and process.code_signature.status : "errorCode_endpoint*")
'''

min_endpoint_version = "8.0.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1555"
name = "Credentials from Password Stores"
reference = "https://attack.mitre.org/techniques/T1555/"
[[threat.technique.subtechnique]]
id = "T1555.004"
name = "Windows Credential Manager"
reference = "https://attack.mitre.org/techniques/T1555/004/"



[threat.tactic]
id = "TA0006"
name = "Credential Access"
reference = "https://attack.mitre.org/tactics/TA0006/"

[internal]
min_endpoint_version = "8.0.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.