Sigma medium test sigma

Credential Manager Access By Uncommon Applications

Detects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function

View Source

Detection Logic

{
  "selection": {
    "FileName
| contains": [
      "\\AppData\\Local\\Microsoft\\Credentials\\",
      "\\AppData\\Roaming\\Microsoft\\Credentials\\",
      "\\AppData\\Local\\Microsoft\\Vault\\",
      "\\ProgramData\\Microsoft\\Vault\\"
    ]
  },
  "filter_main_system_folders": {
    "Image
| startswith": [
      "C:\\Program Files\\",
      "C:\\Program Files (x86)\\",
      "C:\\Windows\\system32\\",
      "C:\\Windows\\SysWOW64\\"
    ]
  },
  "filter_main_explorer": {
    "Image": "C:\\Windows\\explorer.exe"
  },
  "condition": "selection and not 1 of filter_main_*"
}

False Positives

  • Legitimate software installed by the users for example in the "AppData" directory may access these files (for any reason).

Field Validations

Loading…

Comments (0)

Loading comments...