Techniques › T1649 › AN0671
AN0671 Analytic 0671
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Monitor for abnormal certificate enrollment and usage activity in Active Directory Certificate Services (AD CS), registry access to certificate storage locations, and unusual process executions that attempt to export or access private keys.</p>
- Detects
- T1649 Steal or Forge Authentication Certificates
- Part of
- DET0240 Detection Strategy for Steal or Forge Authentication Certificates
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Security | EventCode=4768 | DC0084 Active Directory Credential Request |
| WinEventLog:Security | EventCode=4657 | DC0050 Windows Registry Key Access |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
EKU_Thresholds | Organizations may tune which Extended Key Usage (EKU) values are considered risky. |
TimeWindow | Defines how quickly multiple certificate enrollments from the same entity should trigger correlation alerts. |
LogonContext | Differentiate between service accounts and interactive user accounts to reduce false positives. |