BIOC
Informational
✕
Unsigned process accessed a credential locker file
The credential manager stores credentials for logging in to websites, applications and devices in encrypted Windows Vault Credential Files which can be accessed and decrypted by an attacker.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Credential Access
- Status:
- Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores: Windows Credential Manager (T1555.004)
Indicator:
File action type = all AND file path = *.vcrd , *policy.vpol Process initiator signature = Unsigned , cgo signature = Unsigned , os parent signature = Unsigned Host host os != linux AND host os = windows
Preventable: yes