For the complete documentation index, see llms.txt. This page is also available as Markdown.

A suspicious process enrolled for a certificate

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

Active Directory Certificate Services Analytics

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials (T1552), Steal or Forge Authentication Certificates (T1649)

Severity

Low

Description

A suspicious process enrolled for a certificate.

Attacker's Goals

  • Attackers may authenticate as users using a certificate.

  • If a policy is configured with permissive options, the attacker can authenticate as a user with high privileges.

Investigative actions

  • See whether this was a legitimate action.

  • Follow process/user activities.

  • Check for suspicious certificate authentications.

Variations

An unsigned suspicious process enrolled for a certificate

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Unsecured Credentials (T1552), Steal or Forge Authentication Certificates (T1649)

Severity

Medium

Description

An unsigned suspicious process enrolled for a certificate.

Attacker's Goals

  • Attackers may authenticate as users using a certificate.

  • If a policy is configured with permissive options, the attacker can authenticate as a user with high privileges.

Investigative actions

  • See whether this was a legitimate action.

  • Follow process/user activities.

  • Check for suspicious certificate authentications.

Was this helpful?