Certificate Exported Via PowerShell

 Original Source: [Sigma source]
Title: Certificate Exported Via PowerShell
Status: test
Description:Detects calls to cmdlets that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
References:
  -https://us-cert.cisa.gov/ncas/analysis-reports/ar21-112a
  -https://learn.microsoft.com/en-us/powershell/module/pki/export-pfxcertificate?view=windowsserver2022-ps
  -https://www.splunk.com/en_us/blog/security/breaking-the-chain-defending-against-certificate-services-abuse.html
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-18
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.execution'
  • -'attack.t1552.004'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    CommandLine|contains:
      -'Export-PfxCertificate '
      -'Export-Certificate '

  condition:selection
Falsepositives:
  -Legitimate certificate exports by administrators. Additional filters might be required.
Level: medium