Access To Windows DPAPI Master Keys By Uncommon Applications
Description
Detects file access requests to the the Windows Data Protection API Master keys by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::masterkey" function
Query · sigma
selection: FileName|contains: - \Microsoft\Protect\S-1-5-18\ - \Microsoft\Protect\S-1-5-21- filter_main_system_folders: Image|startswith: - C:\Program Files\ - C:\Program Files (x86)\ - C:\Windows\system32\ - C:\Windows\SysWOW64\ filter_main_explorer: Image: C:\Windows\explorer.exe condition: selection and not 1 of filter_main_*
Known false positives
- Unknown