Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Events for Certificate Exports #2378

Closed
inthecards77 opened this issue Sep 20, 2022 · 3 comments
Closed

Windows Events for Certificate Exports #2378

inthecards77 opened this issue Sep 20, 2022 · 3 comments
Assignees

Comments

@inthecards77
Copy link

I like to track these to look for possible impersonation threat.

Log Name: Microsoft-Windows-CertificateServicesClient-Lifecycle-User/Operational
Source: Microsoft-Windows-CertificateServicesClient-Lifecycle-User
Date: 6/17/2022 12:32:49 PM
Event ID: 1007
Task Category: None
Level: Information
Keywords:
User: HP-AR\inthe
Computer: HP-AR
Description:
A certificate has been exported. Please refer to the "Details" section for more information.

Log Name: Microsoft-Windows-CertificateServicesClient-Lifecycle-System/Operational
Source: Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Date: 6/18/2022 7:53:18 AM
Event ID: 1007
Task Category: None
Level: Information
Keywords:
User: HP-AR\inthe
Computer: HP-AR
Description:
A certificate has been exported. Please refer to the "Details" section for more information.

@MHaggis
Copy link
Contributor

MHaggis commented Oct 9, 2022

Hi @inthecards77 , Thank you for the share. Would you mind sharing a bit more details of the attack or a blog post related? Thank you

@inthecards77
Copy link
Author

inthecards77 commented Oct 10, 2022 via email

@MHaggis
Copy link
Contributor

MHaggis commented Feb 13, 2023

Thank you for this! I dug in on this topic and shipped a good amount of content around certificate services. Thank you!

@MHaggis MHaggis closed this as completed Feb 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants