Analytics BIOC
Low
✕
Certutil pfx parsing
Certutil was used to parse a pfx certificate file.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Local System (T1005)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:
Attackers want to check pfx details. If details suffice, the correct certificate can be used for authentication, persistence or NTLM extraction.
Investigative actions:
Check if the pfx parsing is legitimate for the user (Testing, IT, etc.). Follow further actions done by the user (ex. authentication using certificates).
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day