Credential Manager Access By Uncommon Applications

 Original Source: [Sigma source]
Title: Credential Manager Access By Uncommon Applications
Status: test
Description:Detects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function
References:
  -https://hunter2.gitbook.io/darthsidious/privilege-escalation/mimikatz
  -https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-10-11
modified:2026-07-28
Tags:
  • -'attack.t1003'
  • -'attack.credential-access'
Logsource:
  • category: file_access
  • product: windows
  • definition: Requirements: Microsoft-Windows-Kernel-File ETW provider
Detection:
  selection:
    FileName|contains:
      -'\AppData\Local\Microsoft\Credentials\'
      -'\AppData\Roaming\Microsoft\Credentials\'
      -'\AppData\Local\Microsoft\Vault\'
      -'\ProgramData\Microsoft\Vault\'

  filter_main_system_folders:
    Image|startswith:
      -'C:\Program Files\'
      -'C:\Program Files (x86)\'
      -'C:\Windows\system32\'
      -'C:\Windows\SysWOW64\'

  filter_main_explorer:
    Image: 'C:\Windows\explorer.exe'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Legitimate software installed by the users for example in the "AppData" directory may access these files (for any reason).
Level: medium