Analytics BIOC Informational

A user created a pfx file for the first time

A user created a pfx file for the first time.

Module:
Identity Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:

Attackers may export certificates to pfx files to use them for authentication, persistence or NTLM extraction.

Investigative actions:

Check if the pfx creation is legitimate for the user (testing, IT, etc.). Follow further actions done by the user (ex. authentication using certificates).

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • A user created a pfx in a suspicious folder for the first time Low (parent: Informational)