Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1649

T1649Steal or Forge Authentication Certificates

T1649 — Steal or Forge Authentication Certificates is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 20 detection use cases covering it and 6 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
20Use cases
6Articles
0Sub-techniques
1Tactic

Use cases covering this technique (20)

Certutil exe certificate extraction ESCU actions · alerting P Detect Certify Command Line Arguments ESCU actions · alerting P Detect Certify With PowerShell Script Block Logging ESCU actions · alerting P Detect Certipy File Modifications ESCU actions · alerting P Steal or Forge Authentication Certificates Behavior Identified ESCU actions · alerting P Windows Export Certificate ESCU actions · hunting P Windows Mimikatz Crypto Export File Extensions ESCU actions · hunting P Windows PowerShell Export Certificate ESCU actions · hunting P Windows PowerShell Export PfxCertificate ESCU actions · hunting P Windows Steal Authentication Certificates - ESC1 Abuse ESCU actions · alerting P Windows Steal Authentication Certificates - ESC1 Authentication ESCU actions · alerting P Windows Steal Authentication Certificates Certificate Issued ESCU actions · hunting P Windows Steal Authentication Certificates Certificate Request ESCU actions · hunting P Windows Steal Authentication Certificates CertUtil Backup ESCU actions · hunting P Windows Steal Authentication Certificates CryptoAPI ESCU actions · hunting P Windows Steal Authentication Certificates CS Backup ESCU actions · hunting P Windows Steal Authentication Certificates Export Certificate ESCU actions · hunting P Windows Steal Authentication Certificates Export PfxCertificate ESCU actions · hunting P [LLM] AD CS CA server initiates SMB(445)+LDAP(389) to a non-DC host (Certighost chase relay) Bespoke exploit · hunting DSPCS [LLM] Domain Controller machine account obtains TGT via PKINIT certificate (Certighost impersonation) Bespoke exploit · hunting SΣP

Articles citing this technique (6)