Credential Manager & DPAPI Secret Access via cmdkey, vaultcmd, or Script Engine
Detects potential credential harvesting attempts by monitoring for the usage of Windows credential management tools (cmdkey.exe and vaultcmd.exe) and the loading of sensitive DLLs (vaultcli.dll, dpapi.dll) by non-Microsoft signed processes, which is commonly used to access stored credentials in the Windows Vault or by DPAPI-protected stores.
SentinelOne

