HackTool - Certify Execution

 Original Source: [Sigma source]
Title: HackTool - Certify Execution
Status: test
Description:Detects Certify a tool for Active Directory certificate abuse based on PE metadata characteristics and common command line arguments.
References:
  -https://github.com/GhostPack/Certify
Author: pH-T (Nextron Systems)
Date: 2023-04-17
modified:2023-04-25
Tags:
  • -'attack.discovery'
  • -'attack.credential-access'
  • -'attack.t1649'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\Certify.exe' OriginalFileName:'Certify.exe' Description|contains:'Certify'   selection_cli_commands:
    CommandLine|contains:
      -'.exe cas '
      -'.exe find '
      -'.exe pkiobjects '
      -'.exe request '
      -'.exe download '

  selection_cli_options:
    CommandLine|contains:
      -' /vulnerable'
      -' /template:'
      -' /altname:'
      -' /domain:'
      -' /path:'
      -' /ca:'

  condition:selection_img or all of selection_cli_*
Falsepositives:
  -Unknown
Level: high