SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows

Flags SharpDPAPI executions on Windows by combining SharpDPAPI PE metadata with distinctive DPAPI-related CommandLine arguments.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-06-26
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies execution of SharpDPAPI.exe by matching the process image path or PE metadata (OriginalFileName) and corroborating the command line with SharpDPAPI-specific arguments and option patterns. Attackers may use SharpDPAPI to interact with DPAPI-related secrets and encryption material as part of credential and privilege escalation activity. Telemetry relies on Windows process creation events including the executable image name and full command line, plus PE metadata fields when available.

Related detections9 linkedT1134.001 — drag to rearrange
SharpImpersonation Tool Execution on Windows
Windows Process Creation: Impersonate.exe HackTool Execution
Malicious Potato Family Privilege Escalation Tool Execution (via process_creation)
Masquerading Cobalt Strike GetSystem Named-Pipe Impersonation Pattern (via process_creation)
Malicious Named Pipe kesknq for Token Impersonation (via pipe_created)
Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
Windows Security 4624 LogonType 9 Impersonation via Negotiate (Advapi) Token Abuse Indicator
Windows: Detect Named Pipe Creation with Koh Default Names
Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Pivot detection · T1134.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.