Credential Manager Access By Uncommon Applications
Detects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function
Detection logic
selection
FileName|contains:
- \AppData\Local\Microsoft\Credentials\
- \AppData\Roaming\Microsoft\Credentials\
- \AppData\Local\Microsoft\Vault\
- \ProgramData\Microsoft\Vault\filter_main_system_folders
Image|startswith:
- C:\Program Files\
- C:\Program Files (x86)\
- C:\Windows\system32\
- C:\Windows\SysWOW64\filter_main_explorer
Image: C:\Windows\explorer.exeCondition
selection and not 1 of filter_main_*Raw YAML
title: Credential Manager Access By Uncommon Applications
id: 407aecb1-e762-4acf-8c7b-d087bcff3bb6
status: test
description: |
Detects suspicious processes based on name and location that access the windows credential manager and vault.
Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function
references:
- https://hunter2.gitbook.io/darthsidious/privilege-escalation/mimikatz
- https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-10-11
modified: 2026-07-28
tags:
- attack.t1003
- attack.credential-access
logsource:
category: file_access
product: windows
definition: 'Requirements: Microsoft-Windows-Kernel-File ETW provider'
detection:
selection:
FileName|contains:
- '\AppData\Local\Microsoft\Credentials\'
- '\AppData\Roaming\Microsoft\Credentials\'
- '\AppData\Local\Microsoft\Vault\'
- '\ProgramData\Microsoft\Vault\'
filter_main_system_folders:
Image|startswith:
- 'C:\Program Files\'
- 'C:\Program Files (x86)\'
- 'C:\Windows\system32\'
- 'C:\Windows\SysWOW64\'
filter_main_explorer:
Image: 'C:\Windows\explorer.exe'
condition: selection and not 1 of filter_main_*
falsepositives:
- Legitimate software installed by the users for example in the "AppData" directory may access these files (for any reason).
# Increase level after false positives filters are good enough
level: mediumFalse positives
- Legitimate software installed by the users for example in the "AppData" directory may access these files (for any reason).
References
Similar rules
Access To Browser Credential Files By Uncommon Applications
lowwindows · Shares T1003
Access To Chromium Browsers Sensitive Files By Uncommon Applications
lowwindows · Shares T1003
Access To Crypto Currency Wallets By Uncommon Applications
mediumwindows · Shares T1003
Capture Credentials with Rpcping.exe
mediumwindows · Shares T1003