BIOC Informational

Key Certificate Search And Exfiltrate

Possible attempt to search for key certificates and exfiltrate them.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Credential Access
Status:
Enabled
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Private Keys (T1552.004)
Indicator:

Process action type = execution AND target process cmd =~ .*(id_rsa|[.]key|[.]pgp|[.]gpg|[.]ppk|[.]p12|[.]pem|[.]pfx|[.]cer|[.]p7b|[.]asc).*-exec[[:blank:]]+cp[[:blank:]]+.* AND target process name = find

Preventable: yes