Certificate Exported Via PowerShell - ScriptBlock
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects calls to cmdlets inside of PowerShell scripts that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "PowerShell Script Block Logged" AND SCRIPTEXECUTED contains "Export-PfxCertificate,Export-Certificate" AND SCRIPTEXECUTED notcontains "CmdletsToExport = @(" select Action1.HOSTNAME,Action1.MESSAGE,Action1.SCRIPTEXECUTED
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Florian Roth (Nextron Systems)


