Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1649 ✕
Download CSV Show ATT&CK heatmapA suspicious process enrolled for a certificate Low 1 variation
A suspicious process enrolled for a certificate.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials (T1552) Steal or Forge Authentication Certificates (T1649)Required data: XDR AgentDetector tags: Active Directory Certificate Services AnalyticsAttacker's goals: Attackers may authenticate as users using a certificate. If a policy is configured with permissive options, the attacker can authenticate as a user with high privileges.Investigative actions: See whether this was a legitimate action. Follow process/user activities. Check for suspicious certificate authentications.Variations
An unsigned suspicious process enrolled for a certificate
Medium overridden
An unsigned suspicious process enrolled for a certificate. overridden