kevmap

TechniquesT1649 › AN0671

AN0671 Analytic 0671

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitor for abnormal certificate enrollment and usage activity in Active Directory Certificate Services (AD CS), registry access to certificate storage locations, and unusual process executions that attempt to export or access private keys.</p>
Detects
T1649 Steal or Forge Authentication Certificates
Part of
DET0240 Detection Strategy for Steal or Forge Authentication Certificates

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4768DC0084 Active Directory Credential Request
WinEventLog:SecurityEventCode=4657DC0050 Windows Registry Key Access

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
EKU_ThresholdsOrganizations may tune which Extended Key Usage (EKU) values are considered risky.
TimeWindowDefines how quickly multiple certificate enrollments from the same entity should trigger correlation alerts.
LogonContextDifferentiate between service accounts and interactive user accounts to reduce false positives.