LOLBAS reading a Windows credential manager file
Encrypted files under the path AppData\Roaming\Microsoft\Credentials are associated with saved passwords in the Windows system.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Credential Access
- Status:
- Enabled
File file path = *\appdata\roaming\microsoft\credentials\* AND action type = read Process initiated by = regsvcs.exe , schtasks.exe , xwizard.exe , findstr.exe , esentutl.exe , reg.exe , csc.exe , atbroker.exe , print.exe , pcwrun.exe , rpcping.exe , wsreset.exe , replace.exe , mshta.exe , bitsadmin.exe , ieexec.exe , cmd.exe , microsoft.workflow.compiler.exe , runscripthelper.exe , makecab.exe , forfiles.exe , control.exe , msbuild.exe , register-cimprovider.exe , ie4uinit.exe , sc.exe , bash.exe , hh.exe , jsc.exe , scriptrunner.exe , odbcconf.exe , extexport.exe , msdt.exe , diskshadow.exe , extrac32.exe , eventvwr.exe , mavinject.exe , regasm.exe , gpscript.exe , rundll32.exe , regsvr32.exe , regedit.exe , msiexec.exe , presentationhost.exe , wmic.exe , runonce.exe , syncappvpublishingserver.exe , verclsid.exe , infdefaultinstall.exe , expand.exe , installutil.exe , wab.exe , dnscmd.exe , at.exe , pcalua.exe , msconfig.exe , powershell.exe , powershell_ise.exe , python.exe , certutil.exe , cmstp.exe , wscript.exe , cscript.exe , perl.exe , ruby.exe AND cgo name != amazonassistantservice.exe AND venm.exe
Preventable: yes