Credential Manager Access By Uncommon Applications
Description
Detects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function
Query · sigma
selection: FileName|contains: - \AppData\Local\Microsoft\Credentials\ - \AppData\Roaming\Microsoft\Credentials\ - \AppData\Local\Microsoft\Vault\ - \ProgramData\Microsoft\Vault\ filter_main_system_folders: Image|startswith: - C:\Program Files\ - C:\Program Files (x86)\ - C:\Windows\system32\ - C:\Windows\SysWOW64\ filter_main_explorer: Image: C:\Windows\explorer.exe condition: selection and not 1 of filter_main_*
Known false positives
- Legitimate software installed by the users for example in the "AppData" directory may access these files (for any reason).