LoFP LoFP / t1003.004

t1003.004

TitleTags
administrator may change this registry setting.
av signature updates
dumping hives for legitimate purpouse i.e. backup or forensic investigation
files with mimikatz in their filename
if a computer is a member of a domain, dpapi has a backup mechanism to allow unprotection of the data. which will trigger this event.
legitimate administrator using credential dumping tool for password recovery
legitimate administrator using tool for password recovery
naughty administrators
unlikely