Analytics BIOC Low

Certutil pfx parsing

Certutil was used to parse a pfx certificate file.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data from Local System (T1005)
Detector tags: Active Directory Certificate Services Analytics
Attacker's goals:

Attackers want to check pfx details. If details suffice, the correct certificate can be used for authentication, persistence or NTLM extraction.

Investigative actions:

Check if the pfx parsing is legitimate for the user (Testing, IT, etc.). Follow further actions done by the user (ex. authentication using certificates).

Test period:
N/A (single event)
Deduplication:
1 Day