Access To Windows Credential History File By Uncommon Applications (7a2a22ea-a203-4cd3-9abf-20eb1c5c6cd2)
Detects file access requests to the Windows Credential History File by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::credhist" function