Certificate Exported From Local Certificate Store

 Original Source: [Sigma source]
Title: Certificate Exported From Local Certificate Store
Status: test
Description:Detects when an application exports a certificate (and potentially the private key as well) from the local Windows certificate store.
References:
  -https://www.splunk.com/en_us/blog/security/breaking-the-chain-defending-against-certificate-services-abuse.html
Author: Zach Mathis
Date: 2023-05-13
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1649'
Logsource:
  • product: windows
  • service: certificateservicesclient-lifecycle-system
Detection:
  selection:
    EventID: '1007'
  condition:selection
Falsepositives:
  -Legitimate application requesting certificate exports will trigger this. Apply additional filters as needed
Level: medium