Unusual access to Windows Credential history files
Detects unusual accesses to the Windows Credential history file. The CREDHIST file contains all previous password-linked master key hashes used by DPAPI to protect secrets on the device. Adversaries may obtain credentials from the Windows Credentials Manager.
- Platform: Windows
- Severity: High
- MITRE Tactic: Credential Access
- MITRE Techniques: T1555, T1555.004