Steal or Forge Authentication Certificates T1649
Tactic: Credential Access
Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital certificates are often used to sign and encrypt messages and/or files. Certificates are also used as authentication material. For example, Entra ID device certificates and Active Directory Certificate Services (AD CS) certificates bind to an identity and can be used as credentials for domain accounts.
Events covered
14 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 34 rules share fields, values, and exclusions.
Fields filtered most (39 distinct)
These fields appear most often in rule filters.
Top indicator values (157 distinct)
These values appear most often in rule predicates.
Exclusions (10 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 7 rules
- ADCS - Certighost CDC Chase Certificate Request (CVE-2026-54121)
- ADCS - Certighost Certificate Issued via CDC Chase (CVE-2026-54121)
- ADCS - Certighost Ghost Machine Account Creation
- Certificate Exported From Local Certificate Store
- Certificate Private Key Acquired
- HackTool - Certify Execution
- HackTool - Certipy Execution
Elastic 5 rules
- Access to a Sensitive LDAP Attribute
- Azure AKS Certificate Signing Request Created or Approved
- Kerberos Config File Accessed by Untrusted or Unsigned Process
- Potential CertiGhost AD CS Machine Identity Mismatch (CVE-2026-54121)
- Potential Invoke-Mimikatz PowerShell Script
Splunk 22 rules
- Certificate Abuse - Windows (Sysmon)
- Certificate Abuse - Windows (Windows Event Log)
- Certificate Enumeration - Windows (Sysmon)
- Certificate Enumeration - Windows (Windows Event Log)
- Certutil exe certificate extraction
- Detect Certify Command Line Arguments
- Detect Certify With PowerShell Script Block Logging
- Detect Certipy File Modifications
- Steal or Forge Authentication Certificates Behavior Identified
- Windows Export Certificate
- Windows Mimikatz Crypto Export File Extensions
- Windows PowerShell Export Certificate
- Windows PowerShell Export PfxCertificate
- Windows Steal Authentication Certificates - ESC1 Abuse
- Windows Steal Authentication Certificates - ESC1 Authentication
- Windows Steal Authentication Certificates Certificate Issued
- Windows Steal Authentication Certificates Certificate Request
- Windows Steal Authentication Certificates CertUtil Backup
- Windows Steal Authentication Certificates CryptoAPI
- Windows Steal Authentication Certificates CS Backup
- Windows Steal Authentication Certificates Export Certificate
- Windows Steal Authentication Certificates Export PfxCertificate