Potential Discovery of Windows Credential Manager Store
Description
Identifies an unusual process accessing User or System Windows Credential Manager Files. Adversaries may attempt to list and acquire credentials from the Windows Credential Manager.
Query · eql
file where event.action == "open" and
file.path : ("?:\\Users\\*\\AppData\\*\\Microsoft\\Credentials\\*",
"?:\\Windows\\System32\\config\\systemprofile\\AppData\\*\\Microsoft\\Credentials\\*") and
not file.name : ("desktop.ini", ".ignore", ".rgignore", "exclude", ".gitignore", ".fdignore") and
not file.extension : "?*" and file.name != null and
process.executable != null and
user.id like ("S-1-5-21*", "S-1-12-*") and
not process.executable :
("?:\\Program Files\\*",
"?:\\Program Files (x86)\\*",
"?:\\Windows\\System32\\lsass.exe",
"?:\\Windows\\System32\\svchost.exe",
"?:\\Windows\\System32\\Robocopy.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\*.exe",
"?:\\ProgramData\\Microsoft\\Windows Defender Advanced Threat Protection\\Platform\\*.exe",
"?:\\Program Files\\Windows Defender Advanced Threat Protection\\*.exe",
"?:\\Program Files\\Microsoft Monitoring Agent\\Agent\\*.exe",
"?:\\Windows\\System32\\SearchIndexer.exe",
"?:\\Windows\\System32\\control.exe",
"System",
"D:\\supergrate*.exe",
"D:\\New folder\\SuperGrate\\*.exe",
"?:\\Windows\\ccmcache\\*.exe",
"?:\\WINDOWS\\CCM\\*.exe",
"C:\\Source\\msert.exe",
"?:\\Windows\\SysWOW64\\prevhost.exe",
"?:\\Windows\\System32\\prevhost.exe",
"?:\\Veritas\\NetBackup\\bin\\bpbkar32.exe",
"?:\\Windows\\System32\\taskhostw.exe",
"?:\\Windows\\System32\\taskhost.exe",
"?:\\Windows\\System32\\sdiagnhost.exe",
"?:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
"?:\\Windows\\System32\\dllhost.exe",
"?:\\Windows\\System32\\CompMgmtLauncher.exe",
"?:\\Windows\\explorer.exe",
"?:\\Windows\\System32\\MRT.exe",
"?:\\Users\\*\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe",
"?:\\Windows\\Microsoft.NET\\Framework\\*\\csc.exe",
"?:\\Windows\\System32\\SearchProtocolHost.exe",
"?:\\Users\\*\\AppData\\Local\\ESET\\ESETOnlineScanner\\ESETOnlineScanner.exe",
"\\Device\\Mup\\*",
"D:\\*\\X64\\loadstate.exe",
"\\Device\\HarddiskVolume?\\Windows\\System32\\*.exe",
"\\Device\\HarddiskVolume?\\Windows\\SysWOW64\\*.exe") and
not (process.code_signature.subject_name :
("Big Angry Dog Ltd",
"Malwarebytes Inc",
"Malwarebytes Corporation",
"Nicholas Anderson",
"ForensiT Limited",
"Johannes Schindelin",
"ITPRODUCTDEV LTD",
"JAM Software GmbH",
"GRAPHISOFT SE",
"Anysphere, Inc.") and process.code_signature.trusted == true) and
not process.thread.Ext.call_stack_summary in ("ntdll.dll|sophosed.dll|apphelp.dll|kernelbase.dll|migcore.dll|migstore.dll|migcore.dll|scanstate.exe|kernel32.dll|ntdll.dll",
"ntdll.dll|sophosed.dll|apphelp.dll|kernelbase.dll|migcore.dll|loadstate.exe|kernel32.dll|ntdll.dll")