Detection rules › Sigma

DPAPI Domain Master Key Backup Attempt

Severity
medium
Author
Roberto Rodriguez @Cyb3rWard0g
Source
upstream

Detects anyone attempting a backup for the DPAPI Master Key. This events gets generated at the source and not the Domain Controller.

MITRE ATT&CK coverage

TacticTechniques
Credential AccessT1003.004 OS Credential Dumping: LSA Secrets

Event coverage

ProviderEvent IDTitle
Security-Auditing4692Backup of data protection master key was attempted.

Stages and Predicates

Stage 1: selection