This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Certificate Exported Via PowerShell - ScriptBlock
Original Source:
[Sigma source]
Title:
Certificate Exported Via PowerShell - ScriptBlock
Status:
test
Description:
Detects calls to cmdlets inside of PowerShell scripts that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
References:
-https://us-cert.cisa.gov/ncas/analysis-reports/ar21-112a
-https://learn.microsoft.com/en-us/powershell/module/pki/export-pfxcertificate?view=windowsserver2022-ps
-https://www.splunk.com/en_us/blog/security/breaking-the-chain-defending-against-certificate-services-abuse.html
Author:
Florian Roth (Nextron Systems)
Date:
2021-04-23
modified:
2023-05-18
Tags:
-'attack.credential-access'
-'attack.t1552.004'
Logsource:
product: windows
category: ps_script
definition: Requirements: Script Block Logging must be enabled
Detection:
selection:
ScriptBlockText|contains
:
-'Export-PfxCertificate'
-'Export-Certificate'
filter_optional_module_export:
ScriptBlockText|contains
:
'CmdletsToExport = @('
condition
:
selection and not 1 of filter_optional_*
Falsepositives:
-Legitimate certificate exports by administrators. Additional filters might be required.
Level:
medium