Detection rules › Sigma

Certificate Exported From Local Certificate Store

Severity
medium
Author
Zach Mathis
Source
upstream

Detects when an application exports a certificate (and potentially the private key as well) from the local Windows certificate store.

MITRE ATT&CK coverage

TacticTechniques
Credential AccessT1649 Steal or Forge Authentication Certificates

Event coverage

ProviderEvent IDTitle
CertificateServicesClient-Lifecycle-System1007A certificate has been exported.

Stages and Predicates

Stage 1: selection

Neighbors

Stricter alternatives (narrower than this rule)

The rules below may be useful if you find the current rule is too noisy / lacks specificity.