Steal or Forge Authentication Certificates

T1649

Technique.View on attack.mitre.org

About this technique

Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital certificates are often used to sign and encrypt messages and/or files. Certificates are also used as authentication material. For example, Entra ID device certificates and Active Directory Certificate Services (AD CS) certificates bind to an identity and can be used as credentials for domain accounts.

Authentication certificates can be both stolen and forged. For example, AD CS certificates can be stolen from encrypted storage (in the Registry or files), misplaced certificate files (i.e. Unsecured Credentials), or directly from the Windows certificate store via various crypto APIs. With appropriate enrollment rights, users and/or machines within a domain can also request and/or manually renew certificates from enterprise certificate authorities (CA). This enrollment process defines various settings and permissions associated with the certificate. Of note, the certificate’s extended key usage (EKU) values define signing, encryption, and authentication use cases, while the certificate’s subject alternative name (SAN) values define the certificate owner’s alternate names.

Abusing certificates for authentication credentials may enable other behaviors such as Lateral Movement. Certificate-related misconfigurations may also enable opportunities for Privilege Escalation, by way of allowing users to impersonate or assume privileged accounts or permissions via the identities (SANs) associated with a certificate. These abuses may also enable Persistence via stealing or forging certificates that can be used as Valid Accounts for the duration of the certificate's validity, despite user password resets. Authentication certificates can also be stolen and forged for machine accounts.

Adversaries who have access to root (or subordinate) CA certificate private keys (or mechanisms protecting/managing these keys) may also establish Persistence by forging arbitrary authentication certificates for the victim domain (known as “golden” certificates). Adversaries may also target certificates and related services in order to access other forms of credentials, such as Golden Ticket ticket-granting tickets (TGT) or NTLM plaintext.

Detection rules22

Rules on DetectionCode tagged with T1649.

Sigma4

RuleLevelLog source
HackTool - Certify Executionhighwindows / process_creation
HackTool - Certipy Executionhighwindows / process_creation
Certificate Exported From Local Certificate Storemediumwindows / NULL
Certificate Private Key Acquiredmediumwindows / NULL

Splunk18

RuleTypeRiskData source
Certutil exe certificate extractionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect Certify Command Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect Certify With PowerShell Script Block LoggingTTPNULLPowershell Script Block Logging 4104
Detect Certipy File ModificationsTTPNULLSysmon EventID 11
Steal or Forge Authentication Certificates Behavior IdentifiedCorrelationNULL
Windows Export CertificateAnomalyNULLWindows Event Log CertificateServicesClient 1007
Windows Mimikatz Crypto Export File ExtensionsAnomalyNULLSysmon EventID 11
Windows PowerShell Export CertificateAnomalyNULLPowershell Script Block Logging 4104
Windows PowerShell Export PfxCertificateAnomalyNULLPowershell Script Block Logging 4104
Windows Steal Authentication Certificates - ESC1 AbuseTTPNULLWindows Event Log Security 4886, Windows Event Log Security 4887
Windows Steal Authentication Certificates - ESC1 AuthenticationTTPNULLWindows Event Log Security 4887, Windows Event Log Security 4768
Windows Steal Authentication Certificates Certificate IssuedAnomalyNULLWindows Event Log Security 4887
Windows Steal Authentication Certificates Certificate RequestAnomalyNULLWindows Event Log Security 4886
Windows Steal Authentication Certificates CertUtil BackupAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Steal Authentication Certificates CryptoAPIAnomalyNULLWindows Event Log CAPI2 70

Groups1

Software3

Campaigns0

None recorded.

Procedure examples4

Groups1

Used byProcedure example
GroupAPT29

APT29 has abused misconfigured AD CS certificate templates to impersonate admin users and create additional authentication certificates.

Software3

Used byProcedure example
ToolAADInternals

AADInternals can create and export various authentication certificates, including those associated with Azure AD joined/registered devices.

ToolMimikatz

Mimikatz's `CRYPTO` module can create and export various types of authentication certificates.

MalwareMini Shai-Hulud

Mini Shai-Hulud has collected victim client certificates to assist in signed authentication assertion with Azure environments.

References7

  1. APT29 Deep Look at Credential Roaming Open source
    Thibault Van Geluwe De Berlaere. (2022, November 8). They See Me Roaming: Following APT29 by Taking a Deeper Look at Windows Credential Roaming. Retrieved November 9, 2022.
  2. GitHub CertStealer Open source
    TheWover. (2021, April 21). CertStealer. Retrieved August 2, 2022.
  3. GitHub GhostPack Certificates Open source
    HarmJ0y. (2018, August 22). SharpDPAPI - Certificates. Retrieved August 2, 2022.
  4. Medium Certified Pre Owned Open source
    Schroeder, W. (2021, June 17). Certified Pre-Owned. Retrieved August 2, 2022.
  5. Microsoft AD CS Overview Open source
    Microsoft. (2016, August 31). Active Directory Certificate Services Overview. Retrieved August 2, 2022.
  6. O365 Blog Azure AD Device IDs Open source
    Syynimaa, N. (2022, February 15). Stealing and faking Azure AD device identities. Retrieved August 3, 2022.
  7. SpecterOps Certified Pre Owned Open source
    Schroeder, W. & Christensen, L. (2021, June 22). Certified Pre-Owned - Abusing Active Directory Certificate Services. Retrieved August 2, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.