Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0134 — Detect Suspicious Access to Windows Credential Manager
DET0134

Detect Suspicious Access to Windows Credential Manager

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0378 Analytic 0378
Windows

Detects unauthorized access to Windows Credential Manager through anomalous process execution (vaultcmd.exe, rundll32.exe keymgr.dll), suspicious API calls (CredEnumerateA), or direct file access to Credential Locker files. Correlates process creation with subsequent file reads of .vcrd/.vpol files under user Credential Locker directories.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=10 WinEventLog:Sysmon EventCode=15
[MonitoredPaths] Credential Locker paths such as %Systemdrive%\Users\*\AppData\Local\Microsoft\Credentials and %Systemdrive%\Users\*\AppData\Local\Microsoft\Vault
[TimeWindow] Correlation window between process execution, file access, and API calls
[PrivilegedUsers] Baseline of expected administrative/service accounts with legitimate Credential Manager access

Detected Techniques

1

Details

MITRE ID
DET0134
STIX ID
x-mitre-detection-strategy--119f2b00-82ac-41fb-96ac-728bf56a8a29
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.