A user created a pfx file for the first time
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
Detector Tags
Active Directory Certificate Services Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Unsecured Credentials: Credentials In Files (T1552.001)
Severity
Informational
Description
A user created a pfx file for the first time.
Attacker's Goals
Attackers may export certificates to pfx files to use them for authentication, persistence or NTLM extraction.
Investigative actions
Check if the pfx creation is legitimate for the user (testing, IT, etc.).
Follow further actions done by the user (ex. authentication using certificates).
Variations
PreviousA user connected to a VPN from a new country
NextA user created an abnormal password-protected archive
Was this helpful?
