Microsoft-Windows-CertificateServicesClient-Lifecycle-System

10 events across 1 channel

Event ID 1001: A certificate has been replaced.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational
Level
Informational
Collection Priority
Recommended (NSA)

Description

A certificate has been replaced. Please refer to the "Details" section for more information.

Message #

A certificate has been replaced. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System",
    "guid": "{bc0669e1-a10d-4a78-834e-1ca3c806c93b}",
    "event_source_name": "",
    "event_id": 1001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T23:08:39.437859+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 7080,
      "thread_id": 1724
    },
    "channel": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CertNotificationData": {
      "ProcessName": "taskhostw.exe",
      "AccountName": "ludus\\LAB-DC01$",
      "Context": "Machine",
      "Action": "Renew",
      "OldCertificateDetails": {
        "Thumbprint": "db0fea9b641f3814fc5168ae83ef7839af1bb012",
        "Template": {
          "Name": "DomainController"
        },
        "SubjectNames": {
          "SubjectName": "CN=LAB-DC01.ludus.domain",
          "SubjectName_1": "997a085b-5e01-4f75-9c22-ed3af23d348a",
          "SubjectName_2": "LAB-DC01.ludus.domain"
        },
        "EKUs": {
          "EKU": {
            "Name": "Client Authentication",
            "OID": "1.3.6.1.5.5.7.3.2"
          },
          "EKU_1": {
            "Name": "Server Authentication",
            "OID": "1.3.6.1.5.5.7.3.1"
          }
        },
        "NotValidAfter": "2027-03-13T20:07:39Z"
      },
      "NewCertificateDetails": {
        "Thumbprint": "1a202ed21d19f873e0a448f967dfe428f278fccd",
        "Template": {
          "Name": "DomainController"
        },
        "SubjectNames": {
          "SubjectName": "CN=LAB-DC01.ludus.domain",
          "SubjectName_1": "997a085b-5e01-4f75-9c22-ed3af23d348a",
          "SubjectName_2": "LAB-DC01.ludus.domain"
        },
        "EKUs": {
          "EKU": {
            "Name": "Client Authentication",
            "OID": "1.3.6.1.5.5.7.3.2"
          },
          "EKU_1": {
            "Name": "Server Authentication",
            "OID": "1.3.6.1.5.5.7.3.1"
          }
        },
        "NotValidAfter": "2027-03-13T22:58:39Z"
      }
    }
  },
  "message": ""
}

References #

Event ID 1002: A certificate has expired.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational
Collection Priority
Recommended (NSA)

Description

A certificate has expired. Please refer to the "Details" section for more information.

Message #

A certificate has expired. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Event ID 1003: A certificate is about to expire.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational
Collection Priority
Recommended (NSA)

Description

A certificate is about to expire. Please refer to the "Details" section for more information.

Message #

A certificate is about to expire. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

References #

Event ID 1004: A certificate has been deleted.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational
Level
Informational
Collection Priority
Recommended (NSA)

Description

A certificate has been deleted. Please refer to the "Details" section for more information.

Message #

A certificate has been deleted. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System",
    "guid": "{bc0669e1-a10d-4a78-834e-1ca3c806c93b}",
    "event_source_name": "",
    "event_id": 1004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:16:33.121721+00:00",
    "event_record_id": 1,
    "correlation": {
      "ActivityID": "8B83AF9E-B321-000D-10CD-838B21B3DC01"
    },
    "execution": {
      "process_id": 8232,
      "thread_id": 2328
    },
    "channel": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "CertNotificationData": {
      "ProcessName": "powershell.exe",
      "AccountName": "ludus\\domainadmin",
      "Context": "Machine",
      "CertificateDetails": {
        "Thumbprint": "bd0fed7feaded6142a26dac68454f5e58bec0eaf",
        "SubjectNames": {
          "SubjectName": "CN=evtgen.local",
          "SubjectName_1": "evtgen.local"
        },
        "EKUs": {
          "EKU": {
            "Name": "Client Authentication",
            "OID": "1.3.6.1.5.5.7.3.2"
          },
          "EKU_1": {
            "Name": "Server Authentication",
            "OID": "1.3.6.1.5.5.7.3.1"
          }
        },
        "NotValidAfter": "2027-03-13T20:26:26Z"
      }
    }
  },
  "message": ""
}

References #

Event ID 1005: A certificate has been archived.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational
Level
Informational

Description

A certificate has been archived. Please refer to the "Details" section for more information.

Message #

A certificate has been archived. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System",
    "guid": "{bc0669e1-a10d-4a78-834e-1ca3c806c93b}",
    "event_source_name": "",
    "event_id": 1005,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T23:08:39.464773+00:00",
    "event_record_id": 9,
    "correlation": {},
    "execution": {
      "process_id": 7080,
      "thread_id": 1724
    },
    "channel": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CertNotificationData": {
      "ProcessName": "taskhostw.exe",
      "AccountName": "ludus\\LAB-DC01$",
      "Context": "Machine",
      "CertificateDetails": {
        "Thumbprint": "db0fea9b641f3814fc5168ae83ef7839af1bb012",
        "Template": {
          "Name": "DomainController"
        },
        "SubjectNames": {
          "SubjectName": "CN=LAB-DC01.ludus.domain",
          "SubjectName_1": "997a085b-5e01-4f75-9c22-ed3af23d348a",
          "SubjectName_2": "LAB-DC01.ludus.domain"
        },
        "EKUs": {
          "EKU": {
            "Name": "Client Authentication",
            "OID": "1.3.6.1.5.5.7.3.2"
          },
          "EKU_1": {
            "Name": "Server Authentication",
            "OID": "1.3.6.1.5.5.7.3.1"
          }
        },
        "NotValidAfter": "2027-03-13T20:07:39Z"
      }
    }
  },
  "message": ""
}

References #

Event ID 1006: A new certificate has been installed.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational
Level
Informational
Collection Priority
Recommended (NSA)

Description

A new certificate has been installed. Please refer to the "Details" section for more information.

Message #

A new certificate has been installed. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System",
    "guid": "{bc0669e1-a10d-4a78-834e-1ca3c806c93b}",
    "event_source_name": "",
    "event_id": 1006,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:17:39.800243+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 4972,
      "thread_id": 4200
    },
    "channel": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CertNotificationData": {
      "ProcessName": "taskhostw.exe",
      "AccountName": "ludus\\LAB-DC01$",
      "Context": "Machine",
      "Action": "Enroll",
      "CertificateDetails": {
        "Thumbprint": "db0fea9b641f3814fc5168ae83ef7839af1bb012",
        "Template": {
          "Name": "DomainController"
        },
        "SubjectNames": {
          "SubjectName": "CN=LAB-DC01.ludus.domain",
          "SubjectName_1": "997a085b-5e01-4f75-9c22-ed3af23d348a",
          "SubjectName_2": "LAB-DC01.ludus.domain"
        },
        "EKUs": {
          "EKU": {
            "Name": "Client Authentication",
            "OID": "1.3.6.1.5.5.7.3.2"
          },
          "EKU_1": {
            "Name": "Server Authentication",
            "OID": "1.3.6.1.5.5.7.3.1"
          }
        },
        "NotValidAfter": "2027-03-13T20:07:39Z"
      }
    }
  },
  "message": ""
}

References #

Event ID 1007: A certificate has been exported.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational
Level
Informational
Collection Priority
Recommended (NSA)

Description

A certificate has been exported. Please refer to the "Details" section for more information.

Message #

A certificate has been exported. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System",
    "guid": "{bc0669e1-a10d-4a78-834e-1ca3c806c93b}",
    "event_source_name": "",
    "event_id": 1007,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T23:18:01.045510+00:00",
    "event_record_id": 15,
    "correlation": {
      "ActivityID": "0D26E79C-B333-0002-70D1-280D33B3DC01"
    },
    "execution": {
      "process_id": 12036,
      "thread_id": 13520
    },
    "channel": "Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "CertNotificationData": {
      "ProcessName": "powershell.exe",
      "AccountName": "ludus\\domainadmin",
      "Context": "Machine",
      "CertificateDetails": {
        "Thumbprint": "f3c772f22d13c2ce651009a42dfef27f1b371f59",
        "SubjectNames": {
          "SubjectName": "CN=selftest.ludus.domain",
          "SubjectName_1": "selftest.ludus.domain"
        },
        "EKUs": {
          "EKU": {
            "Name": "Client Authentication",
            "OID": "1.3.6.1.5.5.7.3.2"
          },
          "EKU_1": {
            "Name": "Server Authentication",
            "OID": "1.3.6.1.5.5.7.3.1"
          }
        },
        "NotValidAfter": "2026-04-12T23:18:01Z"
      }
    }
  },
  "message": ""
}

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Splunk # view in coverage

  • Windows Export Certificate source: The following analytic detects the export of a certificate from the Windows Certificate Store. It leverages the Certificates Lifecycle log channel, specifically event ID 1007, to identify this activity. Monitoring certificate exports is…

Event ID 1008: A certificate has been associated with its private key.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational

Description

A certificate has been associated with its private key. Please refer to the "Details" section for more information.

Message #

A certificate has been associated with its private key. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Event ID 1009: A certificate could not be associated with its private key.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational

Description

A certificate could not be associated with its private key. Please refer to the "Details" section for more information.

Message #

A certificate could not be associated with its private key. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Event ID 1010: A certificate has been deleted from Active Directory.

#
Provider
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Channel
Operational

Description

A certificate has been deleted from Active Directory. Please refer to the "Details" section for more information.

Message #

A certificate has been deleted from Active Directory. Please refer to the "Details" section for more information.

Fields #

NameDescription
EventWriteData UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID bc0669e1-a10d-4a78-834e-1ca3c806c93b

Defined in certenroll.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4052, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads