- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
Detects access to the Windows Protected Storage Service (PSS), which manages sensitive user credentials and encrypted data.
This detection monitors Windows Security event logs for Event ID 5145 (A network share object was checked to see whether client can be granted desired access). Specifically, it looks for access to the “protected_storage” named pipe through the IPC$ share, which is commonly used for remote service interaction.
The Protected Storage Service is a critical Windows component that manages and protects sensitive data like passwords, certificates, and private keys. Attackers target this service to extract credentials stored in the system. Direct access to the protected_storage named pipe is unusual and typically indicates an attempt to interact with the service in ways that may facilitate credential theft.
{{host}}
system where the Protected Storage Service access occurred.