Certutil pfx parsing
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Active Directory Certificate Services Analytics
ATT&CK Tactic
Collection (TA0009)
ATT&CK Technique
Data from Local System (T1005)
Severity
Low
Description
Certutil was used to parse a pfx certificate file.
Attacker's Goals
Attackers want to check pfx details. If details suffice, the correct certificate can be used for authentication, persistence or NTLM extraction.
Investigative actions
Check if the pfx parsing is legitimate for the user (Testing, IT, etc.).
Follow further actions done by the user (ex. authentication using certificates).
Was this helpful?
