Protected Storage Service Access via SMB
Identifies remote access to the Windows Protected Storage Service through the IPC$ share. Attackers may abuse this named pipe to interact with the Protected Storage Service and extract sensitive credentials, certificates, or DPAPI backup keys.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/06/26"
3integration = ["system", "windows"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Identifies remote access to the Windows Protected Storage Service through the IPC$ share. Attackers may abuse this
11named pipe to interact with the Protected Storage Service and extract sensitive credentials, certificates, or DPAPI
12backup keys.
13"""
14from = "now-9m"
15index = ["logs-system.security*", "logs-windows.forwarded*", "winlogbeat-*"]
16language = "kuery"
17license = "Elastic License v2"
18name = "Protected Storage Service Access via SMB"
19note = """## Triage and analysis
20
21### Investigating Protected Storage Service Access via SMB
22
23The Protected Storage Service manages sensitive user data such as passwords, certificates, and private keys. Remote
24access to the `protected_storage` named pipe over the IPC$ share is unusual and may indicate an attempt to extract
25credentials or abuse DPAPI to retrieve domain backup keys from domain controllers.
26
27#### Possible investigation steps
28
29- Identify the source system and user account that initiated the access by reviewing `source.ip`, `user.name`, and
30 `winlog.event_data.SubjectUserName`.
31- Determine whether the target host is a domain controller or other high-value system that stores DPAPI backup keys.
32- Review authentication events (4624, 4625) around the alert time to identify how the source authenticated to the
33 target.
34- Investigate other alerts associated with the source host or user during the past 48 hours.
35- Check for follow-on credential access activity such as registry hive access, LSASS access, or lateral movement.
36
37### False positive analysis
38
39- This activity is rarely expected in most environments. If legitimate administrative tooling accesses this pipe,
40 confirm the source, account, and target system before adding an exception.
41
42### Response and remediation
43
44- Initiate the incident response process based on the outcome of the triage.
45- Isolate the source host if unauthorized access is confirmed.
46- Investigate credential exposure and reset passwords for potentially compromised accounts.
47- Review domain controller DPAPI backup key exposure if the target is a domain controller.
48"""
49references = [
50 "https://threathunterplaybook.com/hunts/windows/190620-DomainDPAPIBackupKeyExtraction/notebook.html",
51 "https://www.elastic.co/security-labs/detect-credential-access",
52]
53setup = """## Setup
54
55Audit Detailed File Share must be enabled to generate the events used by this rule.
56Setup instructions: https://ela.st/audit-detailed-file-share
57"""
58risk_score = 73
59rule_id = "9bed06f5-0c32-488a-9353-d565fc9d1573"
60severity = "high"
61tags = [
62 "Domain: Endpoint",
63 "OS: Windows",
64 "Use Case: Threat Detection",
65 "Tactic: Credential Access",
66 "Tactic: Lateral Movement",
67 "Resources: Investigation Guide",
68 "Use Case: Active Directory Monitoring",
69 "Data Source: Windows Security Event Logs",
70 "Noise: High",
71 "Performance: Normal",
72 "Profile: Aggressive",
73 "Rule Type: New Terms",
74 "Platform: Windows",
75]
76timestamp_override = "event.ingested"
77type = "new_terms"
78
79query = '''
80host.os.type:windows and event.category:file and event.code:5145 and
81 winlog.event_data.ShareName:"\\\\*\\IPC$" and
82 winlog.event_data.RelativeTargetName:"protected_storage" and
83 not source.ip:("::" or "::1" or "0.0.0.0" or "127.0.0.1")
84'''
85
86
87[[rule.threat]]
88framework = "MITRE ATT&CK"
89
90[[rule.threat.technique]]
91id = "T1555"
92name = "Credentials from Password Stores"
93reference = "https://attack.mitre.org/techniques/T1555/"
94
95[[rule.threat.technique]]
96id = "T1552"
97name = "Unsecured Credentials"
98reference = "https://attack.mitre.org/techniques/T1552/"
99
100[[rule.threat.technique.subtechnique]]
101id = "T1552.004"
102name = "Private Keys"
103reference = "https://attack.mitre.org/techniques/T1552/004/"
104[rule.threat.tactic]
105id = "TA0006"
106name = "Credential Access"
107reference = "https://attack.mitre.org/tactics/TA0006/"
108
109[[rule.threat]]
110framework = "MITRE ATT&CK"
111
112[[rule.threat.technique]]
113id = "T1021"
114name = "Remote Services"
115reference = "https://attack.mitre.org/techniques/T1021/"
116
117[[rule.threat.technique.subtechnique]]
118id = "T1021.002"
119name = "SMB/Windows Admin Shares"
120reference = "https://attack.mitre.org/techniques/T1021/002/"
121
122[rule.threat.tactic]
123id = "TA0008"
124name = "Lateral Movement"
125reference = "https://attack.mitre.org/tactics/TA0008/"
126
127
128[rule.new_terms]
129field = "new_terms_fields"
130value = ["user.name", "host.name"]
131[[rule.new_terms.history_window_start]]
132field = "history_window_start"
133value = "now-7d"
Triage and analysis
Investigating Protected Storage Service Access via SMB
The Protected Storage Service manages sensitive user data such as passwords, certificates, and private keys. Remote
access to the protected_storage named pipe over the IPC$ share is unusual and may indicate an attempt to extract
credentials or abuse DPAPI to retrieve domain backup keys from domain controllers.
Possible investigation steps
- Identify the source system and user account that initiated the access by reviewing
source.ip,user.name, andwinlog.event_data.SubjectUserName. - Determine whether the target host is a domain controller or other high-value system that stores DPAPI backup keys.
- Review authentication events (4624, 4625) around the alert time to identify how the source authenticated to the target.
- Investigate other alerts associated with the source host or user during the past 48 hours.
- Check for follow-on credential access activity such as registry hive access, LSASS access, or lateral movement.
False positive analysis
- This activity is rarely expected in most environments. If legitimate administrative tooling accesses this pipe, confirm the source, account, and target system before adding an exception.
Response and remediation
- Initiate the incident response process based on the outcome of the triage.
- Isolate the source host if unauthorized access is confirmed.
- Investigate credential exposure and reset passwords for potentially compromised accounts.
- Review domain controller DPAPI backup key exposure if the target is a domain controller.
References
Related rules
- Potential Credential Access via DCSync
- Suspicious Remote Registry Access via SeBackupPrivilege
- Access to a Sensitive LDAP Attribute
- Potential Computer Account NTLM Relay Activity
- Potential Machine Account Relay Attack via SMB