Certificate Exported Via PowerShell - ScriptBlock

 Original Source: [Sigma source]
Title: Certificate Exported Via PowerShell - ScriptBlock
Status: test
Description:Detects calls to cmdlets inside of PowerShell scripts that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
References:
  -https://us-cert.cisa.gov/ncas/analysis-reports/ar21-112a
  -https://learn.microsoft.com/en-us/powershell/module/pki/export-pfxcertificate?view=windowsserver2022-ps
  -https://www.splunk.com/en_us/blog/security/breaking-the-chain-defending-against-certificate-services-abuse.html
Author: Florian Roth (Nextron Systems)
Date: 2021-04-23
modified:2023-05-18
Tags:
  • -'attack.credential-access'
  • -'attack.t1552.004'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains:
      -'Export-PfxCertificate'
      -'Export-Certificate'

  filter_optional_module_export:
    ScriptBlockText|contains: 'CmdletsToExport = @('
  condition:selection and not 1 of filter_optional_*
Falsepositives:
  -Legitimate certificate exports by administrators. Additional filters might be required.
Level: medium