Title:Access To Windows Credential History File By Uncommon Applications Status:test Description:Detects file access requests to the Windows Credential History File by an uncommon application.
This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::credhist" function
References: -https://tools.thehacker.recipes/mimikatz/modules/dpapi/credhist -https://www.passcape.com/windows_password_recovery_dpapi_credhist Author: Nasreddine Bencherchali (Nextron Systems) Date: 2022-10-17 modified:2024-07-29 Tags: