Sigma medium test sigma
Credential Manager Access By Uncommon Applications
Detects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function
Detection Logic
{
"selection": {
"FileName
| contains": [
"\\AppData\\Local\\Microsoft\\Credentials\\",
"\\AppData\\Roaming\\Microsoft\\Credentials\\",
"\\AppData\\Local\\Microsoft\\Vault\\",
"\\ProgramData\\Microsoft\\Vault\\"
]
},
"filter_main_system_folders": {
"Image
| startswith": [
"C:\\Program Files\\",
"C:\\Program Files (x86)\\",
"C:\\Windows\\system32\\",
"C:\\Windows\\SysWOW64\\"
]
},
"filter_main_explorer": {
"Image": "C:\\Windows\\explorer.exe"
},
"condition": "selection and not 1 of filter_main_*"
} False Positives
- ⚠ Legitimate software installed by the users for example in the "AppData" directory may access these files (for any reason).
Field Validations
Loading…
Comments (0)
Loading comments...