Credential Manager Access By Uncommon Applications — Detection Rule

Detects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function

Read the full analysis on IntelFusions