Technique.View on attack.mitre.org
Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital certificates are often used to sign and encrypt messages and/or files. Certificates are also used as authentication material. For example, Entra ID device certificates and Active Directory Certificate Services (AD CS) certificates bind to an identity and can be used as credentials for domain accounts.
Authentication certificates can be both stolen and forged. For example, AD CS certificates can be stolen from encrypted storage (in the Registry or files), misplaced certificate files (i.e. Unsecured Credentials), or directly from the Windows certificate store via various crypto APIs. With appropriate enrollment rights, users and/or machines within a domain can also request and/or manually renew certificates from enterprise certificate authorities (CA). This enrollment process defines various settings and permissions associated with the certificate. Of note, the certificate’s extended key usage (EKU) values define signing, encryption, and authentication use cases, while the certificate’s subject alternative name (SAN) values define the certificate owner’s alternate names.
Abusing certificates for authentication credentials may enable other behaviors such as Lateral Movement. Certificate-related misconfigurations may also enable opportunities for Privilege Escalation, by way of allowing users to impersonate or assume privileged accounts or permissions via the identities (SANs) associated with a certificate. These abuses may also enable Persistence via stealing or forging certificates that can be used as Valid Accounts for the duration of the certificate's validity, despite user password resets. Authentication certificates can also be stolen and forged for machine accounts.
Adversaries who have access to root (or subordinate) CA certificate private keys (or mechanisms protecting/managing these keys) may also establish Persistence by forging arbitrary authentication certificates for the victim domain (known as “golden” certificates). Adversaries may also target certificates and related services in order to access other forms of credentials, such as Golden Ticket ticket-granting tickets (TGT) or NTLM plaintext.
Rules on DetectionCode tagged with T1649.
| Rule | Level | Log source |
|---|---|---|
| HackTool - Certify Execution | high | windows / process_creation |
| HackTool - Certipy Execution | high | windows / process_creation |
| Certificate Exported From Local Certificate Store | medium | windows / NULL |
| Certificate Private Key Acquired | medium | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Certutil exe certificate extraction | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Certify Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect Certify With PowerShell Script Block Logging | TTP | NULL | Powershell Script Block Logging 4104 |
| Detect Certipy File Modifications | TTP | NULL | Sysmon EventID 11 |
| Steal or Forge Authentication Certificates Behavior Identified | Correlation | NULL | |
| Windows Export Certificate | Anomaly | NULL | Windows Event Log CertificateServicesClient 1007 |
| Windows Mimikatz Crypto Export File Extensions | Anomaly | NULL | Sysmon EventID 11 |
| Windows PowerShell Export Certificate | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows PowerShell Export PfxCertificate | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Steal Authentication Certificates - ESC1 Abuse | TTP | NULL | Windows Event Log Security 4886, Windows Event Log Security 4887 |
| Windows Steal Authentication Certificates - ESC1 Authentication | TTP | NULL | Windows Event Log Security 4887, Windows Event Log Security 4768 |
| Windows Steal Authentication Certificates Certificate Issued | Anomaly | NULL | Windows Event Log Security 4887 |
| Windows Steal Authentication Certificates Certificate Request | Anomaly | NULL | Windows Event Log Security 4886 |
| Windows Steal Authentication Certificates CertUtil Backup | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Steal Authentication Certificates CryptoAPI | Anomaly | NULL | Windows Event Log CAPI2 70 |
| Windows Steal Authentication Certificates CS Backup | Anomaly | NULL | Windows Event Log Security 4876 |
| Windows Steal Authentication Certificates Export Certificate | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Steal Authentication Certificates Export PfxCertificate | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has abused misconfigured AD CS certificate templates to impersonate admin users and create additional authentication certificates. |
| Used by | Procedure example |
|---|---|
| ToolAADInternals | AADInternals can create and export various authentication certificates, including those associated with Azure AD joined/registered devices. |
| ToolMimikatz | Mimikatz's `CRYPTO` module can create and export various types of authentication certificates. |
| MalwareMini Shai-Hulud | Mini Shai-Hulud has collected victim client certificates to assist in signed authentication assertion with Azure environments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.