Private Keys Reconnaissance Via CommandLine Tools

 Original Source: [Sigma source]
Title: Private Keys Reconnaissance Via CommandLine Tools
Status: test
Description:Adversaries may search for private key certificate files on compromised systems for insecurely stored credential
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1552.004/T1552.004.md
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
Date: 2021-07-20
modified:2023-03-06
Tags:
  • -'attack.credential-access'
  • -'attack.t1552.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_cmd_img:
Image|endswith:'\cmd.exe' OriginalFileName:'Cmd.Exe'   selection_cmd_cli:
    CommandLine|contains: 'dir '
  selection_pwsh_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_pwsh_cli:
    CommandLine|contains: 'Get-ChildItem '
  selection_findstr:
Image|endswith:'\findstr.exe' OriginalFileName:'FINDSTR.EXE'   selection_ext:
    CommandLine|contains:
      -'.key'
      -'.pgp'
      -'.gpg'
      -'.ppk'
      -'.p12'
      -'.pem'
      -'.pfx'
      -'.cer'
      -'.p7b'
      -'.asc'

  condition:selection_ext and (all of selection_cmd_* or all of selection_pwsh_* or selection_findstr)
Falsepositives:
  -Unknown
Level: medium