APT36 SHEETCREEP: vaultsvc.exe Dropped to AppData\Local\Microsoft\Vault
Detects file creation or modification events within the Windows Credential Vault folder (AppData\Local\Microsoft\Vault), excluding legitimate activity by the 'vaultsvc.exe' process. This could indicate an attempt to access, modify, or exfiltrate stored credentials.
Microsoft Sentinel (KQL)

