BIOC Informational

Unsigned process accessed a credential locker file

The credential manager stores credentials for logging in to websites, applications and devices in encrypted Windows Vault Credential Files which can be accessed and decrypted by an attacker.

Module:
Platform Analytics
Agent event type:
File
Category:
Credential Access
Status:
Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores: Windows Credential Manager (T1555.004)
Indicator:

File action type = all AND file path = *.vcrd , *policy.vpol Process initiator signature = Unsigned , cgo signature = Unsigned , os parent signature = Unsigned Host host os != linux AND host os = windows

Preventable: yes