Certificate Private Key Acquired

 Original Source: [Sigma source]
Title: Certificate Private Key Acquired
Status: test
Description:Detects when an application acquires a certificate private key
References:
  -https://www.splunk.com/en_us/blog/security/breaking-the-chain-defending-against-certificate-services-abuse.html
Author: Zach Mathis
Date: 2023-05-13
modified:None
Tags:
  • -'attack.credential-access'
  • -'attack.t1649'
Logsource:
  • product: windows
  • service: capi2
  • definition: Requirements: The CAPI2 Operational log needs to be enabled
Detection:
  selection:
    EventID: '70'
  condition:selection
Falsepositives:
  -Legitimate application requesting certificate exports will trigger this. Apply additional filters as needed
Level: medium