Windows Security Event 4662 Detects DPAPI Domain Backup Key Extraction from Domain Controllers

Detects read access to LSA secret DPAPI domain backup key objects in Windows Event ID 4662.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Roberto Rodriguez @Cyb3rWard0g (SigmaHQ), DRL 1.1
Published
2019-06-20
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies access to a DPAPI domain backup key stored as a secret object on Windows Domain Controllers by matching Security Event 4662 fields. Attackers may extract DPAPI domain backup keys to enable decryption of protected credentials across accounts. The detection relies on Windows Security auditing telemetry for object access to SecretObject values containing BCKUPKEY, including the specific access mask.

Related detections9 linkedT1003.004 — drag to rearrange
Windows PUA: MemProcFS memory dump mounting via -device
Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Windows Credential Dump Tool Artifacts Written to Disk via File Events
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Windows Security Event 4692 Detecting DPAPI Domain Master Key Backup Attempt
Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Windows Security Event 4662 Detects DPAPI Domain Backup Key Extraction from Domain Controllers
Pivot detection · T1003.004 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.