HackTool - SharpDPAPI Execution

 Original Source: [Sigma source]
Title: HackTool - SharpDPAPI Execution
Status: test
Description:Detects the execution of the SharpDPAPI tool based on CommandLine flags and PE metadata. SharpDPAPI is a C# port of some DPAPI functionality from the Mimikatz project.
References:
  -https://github.com/GhostPack/SharpDPAPI
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2024-06-26
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1134.001'
  • -'attack.t1134.003'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\SharpDPAPI.exe' OriginalFileName:'SharpDPAPI.exe'   selection_other_cli:
    CommandLine|contains:
      -' backupkey '
      -' blob '
      -' certificates '
      -' credentials '
      -' keepass '
      -' masterkeys '
      -' rdg '
      -' vaults '

  selection_other_options_guid:
    CommandLine|contains|all:
      -' {'
      -'}:'

  selection_other_options_flags:
    CommandLine|contains:
      -' /file:'
      -' /machine'
      -' /mkfile:'
      -' /password:'
      -' /pvk:'
      -' /server:'
      -' /target:'
      -' /unprotect'

  condition:selection_img or (selection_other_cli and 1 of selection_other_options_*)
Falsepositives:
  -Unknown
Level: high