Uncommon Applications Access Windows DPAPI Master Key Files

Alerts on unusual process access to Windows DPAPI master key files under Microsoft\Protect.

FreeReviewedSigma · Medium · v2
Product
windows
Category
file_access
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-10-17
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies file access to Windows DPAPI master key directories associated with the local system (S-1-5-18) and user profiles (S-1-5-21-) when the accessing process is not a common, expected application. Attackers may abuse DPAPI master keys to decrypt protected credentials, enabling credential theft and related follow-on activity. The detection relies on Windows file access telemetry that includes the accessed file path and the accessing process image.

Related detections5 linkedT1555.004 — drag to rearrange
Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
Suspicious Windows Credential Manager Enumeration (via process_creation)
Windows Credential History File Access by Uncommon Applications
Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Uncommon Applications Access Windows DPAPI Master Key Files
Pivot detection · T1555.004 · 5 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.