UBA : DPAPI Backup Master Key Recovery Attempted
The QRadar® User Entity Behavior Analytics (UEBA) app supports use cases based on rules for certain behavioral anomalies.
UBA : DPAPI Backup Master Key Recovery Attempted
Enabled by default
False
Default senseValue
10
Description
Detects when recovery is attempted for a DPAPI Master Key.
Support rule
BB:UBA : Common Event Filters
Log source types
Microsoft Windows Security Event Log (EventID: 4693)