heroui logo

Windows PowerShell Export Certificate

Splunk Security Content

View Source
Summary
This analytic rule detects the execution of the PowerShell cmdlet `export-certificate` using Script Block Logging, crucial for identifying potential certificate exfiltration attempts by adversaries on Windows endpoints. Such activities pose significant security risks as stolen certificates can lead to impersonation, decryption of sensitive data, or further attacks on systems. By monitoring this behavior, organizations can prevent unauthorized access to encrypted communications and sensitive information which could otherwise compromise the integrity and confidentiality of their systems.
Categories
  • Endpoint
  • Windows
Data Sources
  • Pod
  • Script
ATT&CK Techniques
  • T1552.004
  • T1552
  • T1649
Created: 2024-11-13