UBA : DPAPI Backup Master Key Recovery Attempted

The QRadar® User Entity Behavior Analytics (UEBA) app supports use cases based on rules for certain behavioral anomalies.

UBA : DPAPI Backup Master Key Recovery Attempted

Enabled by default

False

Default senseValue

10

Description

Detects when recovery is attempted for a DPAPI Master Key.

Support rule

BB:UBA : Common Event Filters

Log source types

Microsoft Windows Security Event Log (EventID: 4693)