mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
63 lines
2.5 KiB
YAML
63 lines
2.5 KiB
YAML
name: Windows Export Certificate
|
|
id: d8ddfa9b-b724-4df9-9dbe-f34cc0936714
|
|
version: 3
|
|
date: '2024-05-16'
|
|
author: Michael Haag, Splunk
|
|
status: production
|
|
type: Anomaly
|
|
description: The following analytic detects the export of a certificate from the Windows
|
|
Certificate Store. It leverages the Certificates Lifecycle log channel, specifically
|
|
event ID 1007, to identify this activity. Monitoring certificate exports is crucial
|
|
as certificates can be used for authentication to VPNs or private resources. If
|
|
malicious actors export certificates, they could potentially gain unauthorized access
|
|
to sensitive systems or data, leading to significant security breaches.
|
|
data_source:
|
|
- Windows Event Log CertificateServicesClient 1007
|
|
search: '`certificateservices_lifecycle` EventCode=1007 | xmlkv UserData_Xml | stats
|
|
count min(_time) as firstTime max(_time) as lastTime by Computer, SubjectName, UserData_Xml
|
|
| rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
|
| `windows_export_certificate_filter`'
|
|
how_to_implement: To implement this analytic, you must collect Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational
|
|
or Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational.
|
|
known_false_positives: False positives may be generated based on an automated process
|
|
or service that exports certificates on the regular. Review is required before setting
|
|
to alert. Monitor for abnormal processes performing an export.
|
|
references:
|
|
- https://atomicredteam.io/defense-evasion/T1553.004/#atomic-test-4---install-root-ca-on-windows
|
|
tags:
|
|
analytic_story:
|
|
- Windows Certificate Services
|
|
asset_type: Endpoint
|
|
confidence: 60
|
|
impact: 60
|
|
message: An certificate was exported on $dest$ from the Windows Certificate Store.
|
|
mitre_attack_id:
|
|
- T1552.004
|
|
- T1552
|
|
- T1649
|
|
observable:
|
|
- name: dest
|
|
type: Hostname
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- dest
|
|
- SubjectName
|
|
- UserData_Xml
|
|
risk_score: 36
|
|
security_domain: endpoint
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data:
|
|
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1649/atomic_red_team/certificateservices-lifecycle.log
|
|
source:
|
|
XmlWinEventLog:Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational
|
|
sourcetype: XmlWinEventLog
|
|
update_timestamp: true
|