Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames

Alerts on Windows file events for DPAPI backup key/certificate filenames ending in .cer/.key/.pfx/.pvk.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
Nounou Mbeiri, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-06-26
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

Identifies Windows file events where the target filename contains DPAPI-related backup key prefixes (ntds_capi_, ntds_legacy_, ntds_unknown_) and ends with certificate/key extensions (.cer, .key, .pfx, .pvk). This pattern is commonly associated with tools that export or steal DPAPI backup keys and certificates, which attackers can use to decrypt protected credentials. Detection relies on file event telemetry that includes the target filename.

Related detections9 linkedT1555 — drag to rearrange
Suspicious SharpDPAPI Machine Masterkey Extraction (via process_creation)
Suspicious ALPHA SPIDER Veeam Backup Credential Extraction (via process_creation)
Malicious User Files Dump via Network Share - DonPapi, Lazagne (via security)
Malicious User Application Credentials Dump via Network Share - DonPapi, Lazagne (via security)
Suspicious Process Memory Read from Proc Mem for Secret Extraction
Malicious Veeam Credential Theft via PowerShell (via ps_script)
Malicious Credential Harvesting via LaZagne (via process_creation)
Suspicious Credential Prompt Phishing via osascript (via process_creation)
Suspicious Double Base64 Decoded Payload Piped to Shell in CI (reviewdog Supply Chain)
Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames
Pivot detection · T1555 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.