Microsoft-Windows-Crypto-DPAPI

28 events across 3 channels

Event IDTitleChannel
1DPAPI created Master key.Operational
2DPAPI deleted Master key.Operational
3Master key access failed.Operational
4Password Change triggered.Operational
5Synchronization of Master keys triggered.Operational
4097DPAPI BackUp service startedBackUpKeySvc
4098DPAPI BackUp service stoppedBackUpKeySvc
4099DPAPI BackUp service setup of preferred backup keys failed.BackUpKeySvc
8193System credentials creation in LSASS failed.Debug
8194DPAPI Master key file open failed.Debug
8195Master key encryption in memory failedDebug
8196Master key decryption in memory failedOperational
8197DPAPI Protect failed.Debug
8198DPAPI Unprotect failed.Operational
8199Synchronization of Master keys failed.Operational
8200Master key's record successfully logged to Diagnostic file.Operational
8201Master key's record failed to log to Diagnostic file.Operational
8202Master Key decryption failed but a record of this key can be found in the …Operational
8203Master Key decryption failed because no record of this key can be found in the …Operational
8204Master Key decryption failed because the encryption cred mismatches the …Operational
8205Master Key decryption failed but the encryption cred matches the decryption …Operational
8206CredHist file decryption failedOperational
8207Diagnostic File operation received a NULL credential key.Operational
12289DPAPI found credential key.Operational
12290Credential key does not exist.Operational
16385DPAPIDefInformationEventDebug
16386DPAPI tried to backup its master key.Operational
16387DPAPI tried to backup its master key.Operational

Event ID 1 — DPAPI created Master key.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational
Level
4
Samples
1

Message

DPAPI created Master key.

 	GUID:	%1
 	User Storage Area:	%2

Fields

NameDescription
MasterKeyGUIDGUID.
UserStorageUser Storage Area.

Example Event

system:
  provider: Microsoft-Windows-Crypto-DPAPI
  guid: 89FE8F40-CDCE-464E-8217-15EF97D4C7C3
  event_source_name: ''
  event_id: 1
  version: 0
  level: 4
  task: 2
  opcode: 0
  keywords: 9223372036854775810
  time_created: '2023-11-06T06:23:22.512371+00:00'
  event_record_id: 51
  correlation:
    ActivityID: 626F7C94-1079-0002-5F7D-6F627910DA01
  execution:
    process_id: 848
    thread_id: 932
  channel: Microsoft-Windows-Crypto-DPAPI/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  MasterKeyGUID: 8E755BE6-88EB-4BF9-8FCE-4B1358A2DEAC
  UserStorage: C:\Windows\system32\Microsoft\Protect\S-1-5-18\User\
message: ''

References

Event ID 2 — DPAPI deleted Master key.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

DPAPI deleted Master key.

 	GUID:	%1
 	User Storage Area:	%2

Fields

NameDescription
GUID
User_Storage_Area
MasterKeyGUID
UserStorage

Event ID 3 — Master key access failed.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Master key access failed.

 	GUID:			%1
 	Success:			%2
 	Last error:		%3
 	Master key disposition:	%3

Fields

NameDescription
GUID
Success
Last_error
MasterKeyGUID
LastError
MasterKeyDisposition

Event ID 4 — Password Change triggered.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Password Change triggered.

 	Status:	%1

Fields

NameDescription
Status

Event ID 5 — Synchronization of Master keys triggered.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational
Level
4
Samples
1

Message

Synchronization of Master keys triggered.

Example Event

system:
  provider: Microsoft-Windows-Crypto-DPAPI
  guid: 89FE8F40-CDCE-464E-8217-15EF97D4C7C3
  event_source_name: ''
  event_id: 5
  version: 0
  level: 4
  task: 2
  opcode: 0
  keywords: 9223372036854775810
  time_created: '2022-04-07T16:57:17.536444+00:00'
  event_record_id: 46
  correlation:
    ActivityID: E0AAB88C-4A9F-0000-71B9-AAE09F4AD801
  execution:
    process_id: 664
    thread_id: 824
  channel: Microsoft-Windows-Crypto-DPAPI/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 4097 — DPAPI BackUp service started

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
BackUpKeySvc
Level
4
Samples
1

Message

DPAPI BackUp service started

Example Event

system:
  provider: Microsoft-Windows-Crypto-DPAPI
  guid: 89FE8F40-CDCE-464E-8217-15EF97D4C7C3
  event_source_name: ''
  event_id: 4097
  version: 0
  level: 4
  task: 1
  opcode: 0
  keywords: 4611686018427387905
  time_created: '2022-04-07T16:53:02.786035+00:00'
  event_record_id: 3
  correlation:
    ActivityID: E0AAB88C-4A9F-0000-71B9-AAE09F4AD801
  execution:
    process_id: 664
    thread_id: 668
  channel: Microsoft-Windows-Crypto-DPAPI/BackUpKeySvc
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 4098 — DPAPI BackUp service stopped

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
BackUpKeySvc

Message

DPAPI BackUp service stopped

Event ID 4099 — DPAPI BackUp service setup of preferred backup keys failed.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
BackUpKeySvc
Level
2
Samples
1

Message

DPAPI BackUp service setup of preferred backup keys failed.
 	%1
 	Error code: %2

Fields

NameDescription
FailureReason
StatusError code.

Example Event

system:
  provider: Microsoft-Windows-Crypto-DPAPI
  guid: 89FE8F40-CDCE-464E-8217-15EF97D4C7C3
  event_source_name: ''
  event_id: 4099
  version: 0
  level: 2
  task: 1
  opcode: 0
  keywords: 4611686018427387905
  time_created: '2022-04-07T17:32:00.129643+00:00'
  event_record_id: 5
  correlation:
    ActivityID: E0AAB88C-4A9F-0000-71B9-AAE09F4AD801
  execution:
    process_id: 664
    thread_id: 4812
  channel: Microsoft-Windows-Crypto-DPAPI/BackUpKeySvc
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  FailureReason: Getting preferred backup key GUID failed.
  Status: '0xc0000034'
message: ''

References

Event ID 8193 — System credentials creation in LSASS failed.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Debug

Message

System credentials creation in LSASS failed. 

 	Status:	%1

Fields

NameDescription
Status

Event ID 8194 — DPAPI Master key file open failed.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Debug

Message

DPAPI Master key file open failed.

 	FileName:	%1
 	Access:	%2

Fields

NameDescription
FileName
Access

Event ID 8195 — Master key encryption in memory failed

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Debug

Message

Master key encryption in memory failed

Event ID 8196 — Master key decryption in memory failed

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational
Level
2
Samples
1

Message

Master key decryption in memory failed

Example Event

system:
  provider: Microsoft-Windows-Crypto-DPAPI
  guid: 89FE8F40-CDCE-464E-8217-15EF97D4C7C3
  event_source_name: ''
  event_id: 8196
  version: 0
  level: 2
  task: 2
  opcode: 0
  keywords: 9223372036854775810
  time_created: '2022-04-07T08:18:33.398223+00:00'
  event_record_id: 25
  correlation:
    ActivityID: 7AAB4249-4A57-0000-F449-AB7A574AD801
  execution:
    process_id: 648
    thread_id: 4060
  channel: Microsoft-Windows-Crypto-DPAPI/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 8197 — DPAPI Protect failed.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Debug

Message

DPAPI Protect failed .

 	Status:	%1
 	ReasonForFailure:	%2

Fields

NameDescription
Status
ReasonForFailure

Event ID 8198 — DPAPI Unprotect failed.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

DPAPI Unprotect failed .

 	Status:	%1
 	ReasonForFailure:	%2

Fields

NameDescription
Status
ReasonForFailure

Event ID 8199 — Synchronization of Master keys failed.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Synchronization of Master keys failed. 

 	Credential Key Identifier:	%1
 	User Name:	%2
 	User Sid:	%3

Fields

NameDescription
Credential_Key_Identifier
User_Name
User_Sid
CredKeyIdentifier
UserName
UserSid

Event ID 8200 — Master key's record successfully logged to Diagnostic file.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational
Level
4
Samples
1

Message

Master key's record successfully logged to Diagnostic file.

 	GUID:	%1
 	EncryptCredID:	%2
 	EncryptCredKey:	%3

Fields

NameDescription
MasterKeyGUIDGUID.
EncryptCredID
EncryptCredKey

Example Event

system:
  provider: Microsoft-Windows-Crypto-DPAPI
  guid: 89FE8F40-CDCE-464E-8217-15EF97D4C7C3
  event_source_name: ''
  event_id: 8200
  version: 0
  level: 4
  task: 32
  opcode: 0
  keywords: 9223372036854775840
  time_created: '2023-11-06T06:23:22.525334+00:00'
  event_record_id: 52
  correlation:
    ActivityID: 626F7C94-1079-0002-5F7D-6F627910DA01
  execution:
    process_id: 848
    thread_id: 888
  channel: Microsoft-Windows-Crypto-DPAPI/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  MasterKeyGUID: 8E755BE6-88EB-4BF9-8FCE-4B1358A2DEAC
  EncryptCredID: 00000000-0000-0000-0000-000000000000
  EncryptCredKey: 0163A518CE6A252FD79B229C27BC6BEB9D05710A
message: ''

References

Event ID 8201 — Master key's record failed to log to Diagnostic file.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Master key's record failed to log to Diagnostic file.

 	GUID:	%1

Fields

NameDescription
GUID
MasterKeyGUID

Event ID 8202 — Master Key decryption failed but a record of this key can be found in the Diagnostic file.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Master Key decryption failed but a record of this key can be found in the Diagnostic file.

 	GUID:	%1

Fields

NameDescription
GUID
MasterKeyGUID

Event ID 8203 — Master Key decryption failed because no record of this key can be found in the Diagnostic file.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Master Key decryption failed because no record of this key can be found in the Diagnostic file.

 	GUID:	%1

Fields

NameDescription
GUID
MasterKeyGUID

Event ID 8204 — Master Key decryption failed because the encryption cred mismatches the decryption cred.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Master Key decryption failed because the encryption cred mismatches the decryption cred.

 	GUID:	%1
 	EncryptCredID:	%2
 	EncryptCredKey:	%3
 	DecryptCredID:	%4
 	DecryptCredKey:	%5

Fields

NameDescription
GUID
EncryptCredID
EncryptCredKey
DecryptCredID
DecryptCredKey
MasterKeyGUID

Event ID 8205 — Master Key decryption failed but the encryption cred matches the decryption cred.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Master Key decryption failed but the encryption cred matches the decryption cred.

 	GUID:	%1
 	EncryptCredID:	%2
 	EncryptCredKey:	%3
 	DecryptCredID:	%4
 	DecryptCredKey:	%5

Fields

NameDescription
GUID
EncryptCredID
EncryptCredKey
DecryptCredID
DecryptCredKey
MasterKeyGUID

Event ID 8206 — CredHist file decryption failed

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

CredHist file decryption failed

Event ID 8207 — Diagnostic File operation received a NULL credential key.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Diagnostic File operation received a NULL credential key.

Event ID 12289 — DPAPI found credential key.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational
Level
4
Samples
1

Message

DPAPI found credential key.

 	Credential Key Identifier:	%1
 	User Name:	%2
 	User Sid:	%3

Fields

NameDescription
CredKeyIdentifierCredential Key Identifier.
UserName
UserSid

Example Event

system:
  provider: Microsoft-Windows-Crypto-DPAPI
  guid: 89FE8F40-CDCE-464E-8217-15EF97D4C7C3
  event_source_name: ''
  event_id: 12289
  version: 0
  level: 4
  task: 8
  opcode: 0
  keywords: 9223372036854775816
  time_created: '2023-11-05T22:32:20.183219+00:00'
  event_record_id: 60
  correlation:
    ActivityID: E4DB489E-1037-0001-0C49-DBE43710DA01
  execution:
    process_id: 808
    thread_id: 844
  channel: Microsoft-Windows-Crypto-DPAPI/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  CredKeyIdentifier: 1252116F853845A8FF2D58933C34AA9AF5F449F00879735FEE2F257A4036020E
  UserName: User
  UserSid: S-1-5-21-1992711665-1655669231-58201500-1000
message: ''

References

Event ID 12290 — Credential key does not exist.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

Credential key does not exist.

Event ID 16385 — DPAPIDefInformationEvent

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Debug

Message

DPAPIDefInformationEvent

Fields

NameDescription
OperationType
DataDescription
MasterKeyGUID
Flags
ProtectionFlags
ReturnValue
CallerProcessStartKey
CallerProcessID
CallerProcessCreationTime
PlainTextDataSize

Community Notes

Exposes the DPAPI operations (protect/unprotect) and the calling process. Disabled by default. See this Google Security blog post: Detecting browser data theft using Windows Event Logs.

Event ID 16386 — DPAPI tried to backup its master key.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

DPAPI tried to backup its master key.
Fallback backup is enabled.

Fields

NameDescription
fLegacy
fWeakCrypt
dwFallbackLastError
dwEncryptLastError
dwRestoreLastError

Event ID 16387 — DPAPI tried to backup its master key.

Provider
Microsoft-Windows-Crypto-DPAPI
Channel
Operational

Message

DPAPI tried to backup its master key.
Fallback backup is disabled.

Fields

NameDescription
fLegacy
fWeakCrypt
dwLastError