Access To Windows Credential History File By Uncommon Applications
Description
Detects file access requests to the Windows Credential History File by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::credhist" function
Query · sigma
selection: FileName|endswith: \Microsoft\Protect\CREDHIST filter_main_system_folders: Image|startswith: - C:\Program Files\ - C:\Program Files (x86)\ - C:\Windows\system32\ - C:\Windows\SysWOW64\ filter_main_explorer: Image: C:\Windows\explorer.exe condition: selection and not 1 of filter_main_*
Known false positives
- Unknown