DPAPI Credential Extraction via dpapi.dll, Mimikatz, or Browser Credential Access
This rule detects various methods used to extract credentials protected by the Windows Data Protection API (DPAPI). It covers multiple vectors, including Mimikatz DPAPI module usage, unauthorized loading of the dpapi.dll library, suspicious access to browser or WiFi credential stores, and cross-process memory access to the LSASS process to extract DPAPI master keys.
SentinelOne

