Sigma medium test sigma

Access To Windows DPAPI Master Keys By Uncommon Applications

Detects file access requests to the the Windows Data Protection API Master keys by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::masterkey" function

View Source

Detection Logic

{
  "selection": {
    "FileName
| contains": [
      "\\Microsoft\\Protect\\S-1-5-18\\",
      "\\Microsoft\\Protect\\S-1-5-21-"
    ]
  },
  "filter_main_system_folders": {
    "Image
| startswith": [
      "C:\\Program Files\\",
      "C:\\Program Files (x86)\\",
      "C:\\Windows\\system32\\",
      "C:\\Windows\\SysWOW64\\"
    ]
  },
  "filter_main_explorer": {
    "Image": "C:\\Windows\\explorer.exe"
  },
  "condition": "selection and not 1 of filter_main_*"
}

False Positives

  • Unknown

Field Validations

Loading…

Comments (0)

Loading comments...