Potential Discovery of DPAPI Master Keys
Description
Identifies an unusual process accessing Data Protection API Master keys. Adversaries may attempt to discover and acquire credentials from the Windows Credential Manager.
Query · eql
file where event.action == "open" and
file.path : ("?:\\USERS\\*\\APPDATA\\*\\MICROSOFT\\PROTECT\\S-1-5-21*\\*",
"?:\\USERS\\*\\APPDATA\\*\\MICROSOFT\\PROTECT\\S-1-12-1-*\\*",
"?:\\WINDOWS\\SYSTEM32\\MICROSOFT\\PROTECT\\S-1-5-18\\USER\\*") and
process.executable : ("C:\\*", "\\Device\\Mup\\*") and
user.id like ("S-1-5-21*", "S-1-12-*") and
not file.name : ("desktop.ini", "exclude", ".fdignore", ".rgignore", ".ignore", ".gitignore") and
not process.executable :
("?:\\Program Files\\*",
"?:\\Program Files (x86)\\*",
"?:\\Windows\\System32\\lsass.exe",
"?:\\Windows\\System32\\svchost.exe",
"?:\\Windows\\System32\\Robocopy.exe",
"System",
"?:\\Windows\\ccmcache\\*.exe",
"?:\\WINDOWS\\CCM\\*.exe",
"?:\\Windows\\SysWOW64\\prevhost.exe",
"?:\\Windows\\System32\\prevhost.exe",
"?:\\Veritas\\NetBackup\\bin\\bpbkar32.exe",
"?:\\Windows\\System32\\taskhostw.exe",
"?:\\Windows\\System32\\taskhost.exe",
"?:\\Windows\\System32\\sdiagnhost.exe",
"?:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
"?:\\$WINDOWS.~BT\\Sources\\setuphost.exe",
"?:\\Windows\\explorer.exe",
"?:\\Windows\\System32\\sppsvc.exe",
"?:\\Windows\\System32\\backgroundTaskHost.exe",
"?:\\Windows\\System32\\dllhost.exe",
"?:\\Windows\\WID\\Binn\\sqlservr.exe",
"?:\\Windows\\System32\\SearchProtocolHost.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\*.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
"?:\\Program Files\\Windows Defender Advanced Threat Protection\\*.exe",
"?:\\Windows\\System32\\igfxtray.exe",
"?:\\$WINDOWS.~BT\\Sources\\SetupCore.exe",
"?:\\Windows\\System32\\pacjsworker.exe",
"?:\\Windows\\System32\\MoUsoCoreWorker.exe",
"?:\\Windows\\System32\\conhost.exe",
"?:\\Windows\\System32\\LocationNotificationWindows.exe",
"?:\\Windows\\System32\\MRT.exe",
"?:\\Windows\\twain_32\\Brimc16a\\Common\\TwDsUiLaunch.exe",
"?:\\Windows\\Microsoft.NET\\Framework64\\*\\csc.exe",
"?:\\Users\\*\\AppData\\Local\\JetBrains\\Toolbox\\apps\\datagrip\\ch-0\\203.5981.102\\bin\\datagrip64.exe",
"?:\\Windows\\cybercnsagent\\osqueryi.exe") and
/* MSSQL service account */
not (process.name : "sqlservr.exe" and file.path : "?:\\Users\\svc_*") and
not (process.name : ("MicrosoftEdgeUpdate.exe", "Teams.exe") and
process.code_signature.subject_name : "Microsoft Corporation" and process.code_signature.trusted == true) and
not (process.code_signature.subject_name : ("ESET, spol. s r.o.", "Intel(R) pGFX", "ForensiT Limited", "Johannes Schindelin") and
process.code_signature.trusted == true) and
not (process.name : "r-LiteCollector.exe" and process.code_signature.status : "errorCode_endpoint*")