Sub-technique of T1552 Unsecured Credentials.View on attack.mitre.org
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.
Adversaries may also look in common key directories, such as ~/.ssh for SSH keys on * nix-based systems or C:\Users\(username)\.ssh\ on Windows. Adversary tools may also search compromised systems for file extensions relating to cryptographic keys and certificates.
When a device is registered to Entra ID, a device key and a transport key are generated and used to verify the device’s identity. An adversary with access to the device may be able to export the keys in order to impersonate the device.
On network devices, private keys may be exported via Network Device CLI commands such as `crypto pki export`.
Some private keys require a password or passphrase for operation, so an adversary may also use Input Capture for keylogging or attempt to Brute Force the passphrase off-line. These private keys can be used to authenticate to Remote Services like SSH or for use in decrypting other collected files such as email.
Rules on DetectionCode tagged with T1552.004.
| Rule | Level | Log source |
|---|---|---|
| Cisco Crypto Commands | high | cisco / NULL |
| DPAPI Backup Keys And Certificate Export Activity IOC | high | windows / file_event |
| PowerShell Get-Process LSASS | high | windows / process_creation |
| Certificate Exported Via PowerShell | medium | windows / process_creation |
| Certificate Exported Via PowerShell - ScriptBlock | medium | windows / ps_script |
| Private Keys Reconnaissance Via CommandLine Tools | medium | windows / process_creation |
| Suspicious PFX File Creation | medium | windows / file_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux Auditd Find Private Keys | TTP | NULL | Linux Auditd Execve |
| Linux Auditd Find Ssh Private Keys | Anomaly | NULL | Linux Auditd Execve |
| Linux Auditd Private Keys and Certificate Enumeration | Anomaly | NULL | Linux Auditd Execve |
| Windows Export Certificate | Anomaly | NULL | Windows Event Log CertificateServicesClient 1007 |
| Windows PowerShell Export Certificate | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Export PfxCertificate | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Private Keys Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupKimsuky | Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`. |
| GroupRocke | Rocke has used SSH private keys on the infected machine to spread its coinminer throughout a network. |
| GroupScattered Spider | Scattered Spider enumerate and exfiltrate code-signing certificates from a compromised host. |
| GroupStorm-0501 | Storm-0501 has leveraged the Azure Owner role to access and steal the Storage Account Access keys using the `Microsoft.Storage/storageAccounts/listkeys/action` operation. |
| GroupTeamPCP | TeamPCP has used malware to extract SSH and GPG keys from victim environments. |
| GroupTeamTNT | TeamTNT has searched for unsecured SSH keys. |
| GroupVolt Typhoon | Volt Typhoon has accessed a Local State file that contains the AES key used to encrypt passwords stored in the Chrome browser. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can gather encryption keys from Azure AD services such as ADSync and Active Directory Federated Services servers. |
| MalwareCanisterWorm | CanisterWorm has gathered SSH private keys from the .ssh file. |
| MalwareEbury | Ebury has intercepted unencrypted private keys as well as private key pass-phrases. |
| ToolEmpire | Empire can use modules like |
| MalwareFoggyWeb | FoggyWeb can retrieve token signing certificates and token decryption certificates from a compromised AD FS server. |
| MalwareHildegard | Hildegard has searched for private keys in .ssh. |
| MalwarejRAT | jRAT can steal keys for VPNs and cryptocurrency wallets. |
| MalwareKinsing | Kinsing has searched for private keys. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Wocao | During Operation Wocao, threat actors used Mimikatz to dump certificates and private keys from the Windows certificate store. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained PKI keys, certificate files, and the private encryption key from an Active Directory Federation Services (AD FS) container to decrypt corresponding SAML signing certificates. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.