{"id":"T1552.004","name":"Private Keys","url":"https://attack.mitre.org/techniques/T1552/004","tactics":["credential-access"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0549","stix_id":"x-mitre-detection-strategy--84b5d372-eedb-4b69-bf78-9d4815e2b2b7","name":"Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0549","analytics":[{"id":"AN1516","stix_id":"x-mitre-analytic--eb569d45-a5b6-47df-a098-bdb26ef0597f","name":"Analytic 1516","description":"A process (non-system or user-initiated) accesses private key files in user profile paths or system certificate stores followed by potential network connections or compression activity.","url":"https://attack.mitre.org/detectionstrategies/DET0549#AN1516","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=5145","data_component":"DC0102","data_component_name":"Network Share Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"FilePathRegex","description":"Regex for matching key file extensions (.pem, .pfx, .ppk, etc.) or known certificate directories like C:\\Users\\*\\.ssh\\"},{"field":"ParentProcessName","description":"Set of known benign certificate management tools to exclude (e.g., certutil.exe, ssh.exe)"}],"live":true,"detection_strategies":["DET0549"],"techniques":["T1552.004"]},{"id":"AN1517","stix_id":"x-mitre-analytic--3577f79d-0891-451b-a861-1a03a3688a93","name":"Analytic 1517","description":"User or script-based access to ~/.ssh or other directories containing private keys followed by unusual shell activity or network connections.","url":"https://attack.mitre.org/detectionstrategies/DET0549#AN1517","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"openat","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"FilePathRegex","description":"Directory/file path regex for ~/.ssh, *.pem, *.key, *.p12"},{"field":"CommandLineMatch","description":"Script or user agent seen accessing keys (e.g., cat ~/.ssh/id_rsa, tar ~/.gnupg)"}],"live":true,"detection_strategies":["DET0549"],"techniques":["T1552.004"]},{"id":"AN1518","stix_id":"x-mitre-analytic--d7a9c7c8-81a0-4988-9617-51f191ab32c8","name":"Analytic 1518","description":"Access to user private key directories (e.g., /Users/*/.ssh) via Terminal, scripting engines, or non-default processes.","url":"https://attack.mitre.org/detectionstrategies/DET0549#AN1518","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"open/read access to private key files (id_rsa, *.pem, *.p12)","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"launch of bash/zsh/python/osascript targeting key file locations","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ProcessName","description":"Processes reading key files (osascript, python, bash, etc.)"},{"field":"FileAccessPath","description":"Private key and certificate paths like /Users/*/.ssh, /Library/Keychains/"}],"live":true,"detection_strategies":["DET0549"],"techniques":["T1552.004"]},{"id":"AN1519","stix_id":"x-mitre-analytic--57a547e1-1086-427c-9ea8-59059dec1938","name":"Analytic 1519","description":"CLI-based export of private key material (e.g., 'crypto pki export') with anomalous user session or AAA role escalation.","url":"https://attack.mitre.org/detectionstrategies/DET0549#AN1519","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"Detected CLI command to export key material","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"CLICommandMatch","description":"Regex for export commands (e.g., crypto pki export, export ssh-key)"},{"field":"AAAUserContext","description":"Source username or role performing export — may tune for known admins"}],"live":true,"detection_strategies":["DET0549"],"techniques":["T1552.004"]}],"live":true,"version":"1.0","techniques":["T1552.004"]}],"sigma_rules":[{"id":"1f978c6a-4415-47fb-aca5-736a44d7ca3d","title":"Cisco Crypto Commands","author":"Austin Clark","status":"test","level":"high","date":"2019-08-12","modified":"2023-01-04","description":"Show when private keys are being exported from the device, or when new certificates are installed","references":["https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-a1-cr-book_chapter_0111.html"],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.credential-access","attack.defense-impairment","attack.t1553.004","attack.t1552.004"],"path":"rules/network/cisco/aaa/cisco_cli_crypto_actions.yml","techniques":["T1553.004","T1552.004"],"cves":[]},{"id":"213d6a77-3d55-4ce8-ba74-fcfef741974e","title":"Private Keys Reconnaissance Via CommandLine Tools","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2021-07-20","modified":"2023-03-06","description":"Adversaries may search for private key certificate files on compromised systems for insecurely stored credential","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1552.004/T1552.004.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1552.004"],"path":"rules/windows/process_creation/proc_creation_win_susp_private_keys_recon.yml","techniques":["T1552.004"],"cves":[]},{"id":"7892ec59-c5bb-496d-8968-e5d210ca3ac4","title":"DPAPI Backup Keys And Certificate Export Activity IOC","author":"Nounou Mbeiri, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2024-06-26","modified":null,"description":"Detects file names with specific patterns seen generated and used by tools such as Mimikatz and DSInternals related to exported or stolen DPAPI backup keys and certificates.\n","references":["https://www.dsinternals.com/en/dpapi-backup-key-theft-auditing/","https://github.com/MichaelGrafnetter/DSInternals/blob/39ee8a69bbdc1cfd12c9afdd7513b4788c4895d4/Src/DSInternals.Common/Data/DPAPI/DPAPIBackupKey.cs#L28-L32"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1555","attack.t1552.004"],"path":"rules/windows/file/file_event/file_event_win_susp_dpapi_backup_and_cert_export_ioc.yml","techniques":["T1555","T1552.004"],"cves":[]},{"id":"9e716b33-63b2-46da-86a4-bd3c3b9b5dfb","title":"Certificate Exported Via PowerShell","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-18","modified":null,"description":"Detects calls to cmdlets that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.","references":["https://us-cert.cisa.gov/ncas/analysis-reports/ar21-112a","https://learn.microsoft.com/en-us/powershell/module/pki/export-pfxcertificate?view=windowsserver2022-ps","https://www.splunk.com/en_us/blog/security/breaking-the-chain-defending-against-certificate-services-abuse.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.execution","attack.t1552.004","attack.t1059.001"],"path":"rules/windows/process_creation/proc_creation_win_powershell_export_certificate.yml","techniques":["T1552.004","T1059.001"],"cves":[]},{"id":"aa7a3fce-bef5-4311-9cc1-5f04bb8c308c","title":"Certificate Exported Via PowerShell - ScriptBlock","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2021-04-23","modified":"2023-05-18","description":"Detects calls to cmdlets inside of PowerShell scripts that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.","references":["https://us-cert.cisa.gov/ncas/analysis-reports/ar21-112a","https://learn.microsoft.com/en-us/powershell/module/pki/export-pfxcertificate?view=windowsserver2022-ps","https://www.splunk.com/en_us/blog/security/breaking-the-chain-defending-against-certificate-services-abuse.html"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.credential-access","attack.t1552.004"],"path":"rules/windows/powershell/powershell_script/posh_ps_export_certificate.yml","techniques":["T1552.004"],"cves":[]},{"id":"b2815d0d-7481-4bf0-9b6c-a4c48a94b349","title":"PowerShell Get-Process LSASS","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-04-23","modified":"2023-01-05","description":"Detects a \"Get-Process\" cmdlet and it's aliases on lsass process, which is in almost all cases a sign of malicious activity","references":["https://web.archive.org/web/20220205033028/https://twitter.com/PythonResponder/status/1385064506049630211"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1552.004"],"path":"rules/windows/process_creation/proc_creation_win_powershell_getprocess_lsass.yml","techniques":["T1552.004"],"cves":[]},{"id":"dca1b3e8-e043-4ec8-85d7-867f334b5724","title":"PFX File Creation","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"low","date":"2020-05-02","modified":"2025-10-19","description":"Detects the creation of PFX files (Personal Information Exchange format).\nPFX files contain private keys and certificates bundled together, making them valuable targets for attackers seeking to:\n\n    - Exfiltrate digital certificates for impersonation or signing malicious code\n    - Establish persistent access through certificate-based authentication\n    - Bypass security controls that rely on certificate validation\n\nAnalysts should investigate PFX file creation events by examining which process created the PFX file and its parent process chain, as well as unusual locations outside standard certificate stores or development environments.\n","references":["https://github.com/OTRF/detection-hackathon-apt29/issues/14","https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/6.B.1_6392C9F1-D975-4F75-8A70-433DEDD7F622.md"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.credential-access","attack.t1552.004","detection.threat-hunting"],"path":"rules-threat-hunting/windows/file/file_event/file_event_win_pfx_file_creation.yml","techniques":["T1552.004"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-57727","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}