HackTool - Certipy Execution
Description
Detects Certipy execution, a tool for Active Directory Certificate Services enumeration and abuse based on PE metadata characteristics and common command line arguments.
Query · sigma
selection_img: - Image|endswith: \Certipy.exe - OriginalFileName: Certipy.exe - Description|contains: Certipy selection_cli_commands: CommandLine|contains: - ' account ' - ' auth ' - ' cert ' - ' find ' - ' forge ' - ' ptt ' - ' relay ' - ' req ' - ' shadow ' - ' template ' selection_cli_flags: CommandLine|contains: - ' -bloodhound' - ' -ca-pfx ' - ' -dc-ip ' - ' -kirbi' - ' -old-bloodhound' - ' -pfx ' - ' -target' - ' -template' - ' -username ' - ' -vulnerable' - auth -pfx - shadow auto - shadow list condition: selection_img or all of selection_cli_*
Known false positives
- Unlikely