Detection rules › Sigma

Certificate Private Key Acquired

Severity
medium
Author
Zach Mathis
Source
upstream

Detects when an application acquires a certificate private key

MITRE ATT&CK coverage

TacticTechniques
Credential AccessT1649 Steal or Forge Authentication Certificates

Event coverage

ProviderEvent IDTitle
CAPI270For more details for this event, please refer to the "Details" section

Stages and Predicates

Stage 1: selection

Neighbors

Stricter alternatives (narrower than this rule)

The rules below may be useful if you find the current rule is too noisy / lacks specificity.