Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)

PremiumReviewedSigma · High · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-08-30
Updated
2026-08-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects attempt to dump DPAPI credentials (Windows Vault, Chrome, RDP, WiFi, Emails, ...) or registry hives via network share via tools like DonPAPI.

Related detections5 linkedT1555.004 — drag to rearrange
Suspicious Windows Credential Manager Enumeration (via process_creation)
Uncommon Applications Access Windows DPAPI Master Key Files
Windows Credential History File Access by Uncommon Applications
Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
Pivot detection · T1555.004 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.