Microsoft-Windows-CAPI2
74 events across 3 channels
Event ID 10 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 11 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
References
Event ID 12 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 13 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 14 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 15 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 16 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 17 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 18 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 19 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 20 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 21 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 22 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 23 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 24 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 30 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 40 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 41 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 42 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 50 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 51 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 52 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 53 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 60 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 70 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
CryptAcquireCertificatePrivateKey | — |
Example Event
system:
provider: Microsoft-Windows-CAPI2
guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
event_source_name: ''
event_id: 70
version: 0
level: 4
task: 70
opcode: 0
keywords: 4611686018427388032
time_created: '2020-07-11T13:21:11.693103Z'
event_record_id: 13969076
correlation: {}
execution:
process_id: 5708
thread_id: 5712
channel: Microsoft-Windows-CAPI2/Operational
computer: wec02
security:
user_id: S-1-5-21-1153173314-1076311963-3278442693-500
user_data:
CryptAcquireCertificatePrivateKey:
Certificate:
'#attributes':
fileRef: 3CD6B0EFAF68549EFE9ED2316426FCD7FF81A6A8.cer
subjectName: wec02.offsec.lan
Flags:
'#attributes':
value: '10000'
CRYPT_ACQUIRE_ALLOW_NCRYPT_KEY_FLAG: 'true'
EventAuxInfo:
'#attributes':
ProcessName: mimikatz.exe
CorrelationAuxInfo:
'#attributes':
TaskId: '{973F48B9-7001-410B-A904-B1DD8692B60A}'
SeqNumber: '2'
Result:
'#attributes':
value: '0'
Sigma Rules
- Certificate Private Key Acquired
Detects when an application acquires a certificate private key
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 71 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 80 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 81 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 82 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 90 — For more details for this event, please refer to the "Details" section
Message
Fields
| Name | Description |
|---|---|
EventWriteData | — |
Event ID 256 — The Cryptographic Services service failed to initialize the Catalog Database.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 257 — The Cryptographic Services service failed to initialize the Catalog Database.
Message
Fields
| Name | Description |
|---|---|
1 | — |
Event ID 512 — The Cryptographic Services service failed to initialize the VSS backup "System Writer" object.
Message
Fields
| Name | Description |
|---|---|
1 | — |
Event ID 513 — Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Message
Fields
| Name | Description |
|---|---|
1 | — |
Event ID 4097 — Successful auto update of third-party root certificate:: Subject: <OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-CAPI2
guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
event_source_name: Microsoft-Windows-CAPI2
event_id: 4097
version: 0
level: 4
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2023-11-05T23:13:48.717808+00:00'
event_record_id: 1679
correlation: {}
execution:
process_id: 1140
thread_id: 1340
channel: Application
computer: WinDev2310Eval
security:
user_id: ''
event_data:
Data:
- OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US
- 2796BAE63F1801E277261BA0D77770028F20EEE4
message: 'Successful auto update of third-party root certificate:: Subject: <OU=Go
Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US> Sha1
thumbprint: <2796BAE63F1801E277261BA0D77770028F20EEE4>.'
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 4098 — Successful auto update retrieval of third-party root list cab from: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
Event ID 4099 — Failed auto update retrieval of third-party root list cab from: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4100 — Successful auto update retrieval of third-party root certificate from: <.
Message
Fields
| Name | Description |
|---|---|
URL | — |
Example Event
system:
provider: Microsoft-Windows-CAPI2
guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
event_source_name: Microsoft-Windows-CAPI2
event_id: 4100
version: 0
level: 4
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2016-08-24T21:26:02.343750Z'
event_record_id: 1650
correlation: {}
execution:
process_id: 1124
thread_id: 1712
channel: Application
computer: IE10Win7
security:
user_id: ''
event_data: {}
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4101 — Failed auto update retrieval of third-party root certificate from: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4102 — Reached crypt32 threshold of %1 events and will suspend logging for %2 minutes.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4103 — Successful auto update retrieval of third-party root list sequence number from: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
Event ID 4104 — Failed auto update retrieval of third-party root list sequence number from: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4105 — Untrusted root certificate:: Subject: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4106 — Partial Chain:: Issuer: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4107 — Failed extract of third-party root list from auto update cab at: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
References
Event ID 4108 — Successful auto delete of third-party root certificate:: Subject: <OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-CAPI2
guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
event_source_name: Microsoft-Windows-CAPI2
event_id: 4108
version: 0
level: 4
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2022-04-07T17:04:18.250448+00:00'
event_record_id: 217
correlation: {}
execution:
process_id: 2432
thread_id: 2344
channel: Application
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: ''
event_data:
Data:
- OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US
- 4F65566336DB6598581D584A596C87934D5F2AB4
message: 'Successful auto delete of third-party root certificate:: Subject: <OU=Class
3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US> Sha1 thumbprint:
<4F65566336DB6598581D584A596C87934D5F2AB4>.'
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4109 — Successful auto property update of third-party root certificate:: Subject: <OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-CAPI2
guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
event_source_name: Microsoft-Windows-CAPI2
event_id: 4109
version: 0
level: 4
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2022-04-07T17:04:18.250448+00:00'
event_record_id: 216
correlation: {}
execution:
process_id: 2432
thread_id: 2344
channel: Application
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: ''
event_data:
Data:
- OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US
- 742C3192E607E424EB4549542BE1BBC53E6174E2
message: 'Successful auto property update of third-party root certificate:: Subject:
<OU=Class 3 Public Primary Certification Authority, O="VeriSign, Inc.", C=US> Sha1
thumbprint: <742C3192E607E424EB4549542BE1BBC53E6174E2>.'
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 4110 — Failed to add certificate to Third-Party Root Certification Authorities store with error.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4111 — Successful auto update of third-party root list with effective date: Tuesday, February 22, 2022 11:44:40 AM.
Message
Fields
| Name | Description |
|---|---|
Data | Successful auto update of third-party root list with effective date. |
Example Event
system:
provider: Microsoft-Windows-CAPI2
guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
event_source_name: Microsoft-Windows-CAPI2
event_id: 4111
version: 0
level: 4
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2022-04-07T17:04:18.250448+00:00'
event_record_id: 218
correlation: {}
execution:
process_id: 2432
thread_id: 2344
channel: Application
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: ''
event_data:
Data:
- Tuesday, February 22, 2022 11:44:40 AM
message: 'Successful auto update of third-party root list with effective date: Tuesday,
February 22, 2022 11:44:40 AM.'
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 4112 — Successful auto update of disallowed certificate list with effective date: Tuesday, March 16, 2021 12:29:24 AM.
Message
Fields
| Name | Description |
|---|---|
Data | Successful auto update of disallowed certificate list with effective date. |
Example Event
system:
provider: Microsoft-Windows-CAPI2
guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
event_source_name: Microsoft-Windows-CAPI2
event_id: 4112
version: 0
level: 4
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2022-04-07T08:11:02.801955+00:00'
event_record_id: 49
correlation: {}
execution:
process_id: 2436
thread_id: 4712
channel: Application
computer: WIN-FPV0DSIC9O6
security:
user_id: ''
event_data:
Data:
- Tuesday, March 16, 2021 12:29:24 AM
message: 'Successful auto update of disallowed certificate list with effective date:
Tuesday, March 16, 2021 12:29:24 AM.'
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 4113 — Successful auto update of pin rules with effective date: Wednesday, May 31, 2017 4:28:59 PM.
Message
Fields
| Name | Description |
|---|---|
Data | Successful auto update of pin rules with effective date. |
Example Event
system:
provider: Microsoft-Windows-CAPI2
guid: '{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}'
event_source_name: Microsoft-Windows-CAPI2
event_id: 4113
version: 0
level: 4
task: 0
opcode: 0
keywords: 9259400833873739776
time_created: '2022-04-07T08:12:04.333773+00:00'
event_record_id: 82
correlation: {}
execution:
process_id: 2436
thread_id: 5476
channel: Application
computer: WIN-FPV0DSIC9O6
security:
user_id: ''
event_data:
Data:
- Wednesday, May 31, 2017 4:28:59 PM
message: 'Successful auto update of pin rules with effective date: Wednesday, May
31, 2017 4:28:59 PM.'
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4114 — Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
3 | — |
4 | — |
5 | — |
6 | — |
7 | — |
Event ID 4115 — Added public key pinning rule for domain: %1 with header thumbprint: %2.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
3 | — |
Event ID 4116 — Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
3 | — |
4 | — |
5 | — |
6 | — |
7 | — |
Event ID 4117 — Server: %1 has unexpected certificates under trusted authority: <%2> with thumbprint: %3.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
3 | — |
4 | — |
5 | — |
6 | — |
7 | — |
8 | — |
9 | — |
10 | — |
Event ID 4128 — Successful pre-fetch of certificate revocation list from: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
Event ID 4129 — Failed pre-fetch of certificate revocation list from: <.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4130 — Certificate signature verify failed.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4131 — LDAP CryptRetrieveObjectByUrlW failed.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4176 — PFX operation failed as AuthSafes count doesn't lie in expected range.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4177 — PFX operation failed as Iteration count doesn't lie in expected range.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 4178 — PFX operation failed as SafeBags count doesn't lie in expected range.
Message
Fields
| Name | Description |
|---|---|
1 | — |
2 | — |
Event ID 8192 — The catalog file %2 is being added to subsystem %1.
Message
Fields
| Name | Description |
|---|---|
Subsystem | — |
FileName | — |
Event ID 8193 — Addition of the catalog file completed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 8194 — The catalog file %2 is being removed from the subsystem %1.
Message
Fields
| Name | Description |
|---|---|
Subsystem | — |
FileName | — |
Event ID 8195 — Removal of the catalog file completed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 8196 — The catalog file %2 is being synced to the subsystem %1.
Message
Fields
| Name | Description |
|---|---|
Subsystem | — |
FileName | — |
Event ID 8197 — Sync of the catalog file completed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 8198 — The Catalog Database is being rebuilt for subsystem %1.
Message
Fields
| Name | Description |
|---|---|
Subsystem | — |
Event ID 8199 — Rebuild of the Catalog Database for the chosen subsystem has completed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 8200 — A hash of type %2, length %3 and value %4 is being searched for in subsystem %1.
Message
Fields
| Name | Description |
|---|---|
Subsystem | — |
Algorithm | — |
Length | — |
Value | — |
Event ID 8201 — The hash search completed and was found in %2 catalogs.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Count | — |
Event ID 8202 — Sync of subsystem %1 has started.
Message
Fields
| Name | Description |
|---|---|
Subsystem | — |
Event ID 8203 — Sync of the subsystem completed.
Message
Fields
| Name | Description |
|---|---|
Status | — |