Windows CAPI2 Event 70: Certificate Private Key Acquired

Detects when Windows CAPI2 logs that a process acquired a certificate private key (EventID 70).

FreeReviewedSigma · Medium · v2
Product
windows
Service
capi2
Author
Zach Mathis (SigmaHQ), DRL 1.1
Published
2023-05-13
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags CAPI2 Operational events where an application acquires (exports) a certificate private key. Attackers may seek private keys to impersonate identities, decrypt protected content, or facilitate further credential access. It relies on Windows CAPI2 Operational logging (EventID 70) indicating certificate private key acquisition.

Related detections4 linkedT1649 — drag to rearrange
Suspicious LDAP Enumeration of Certificate Templates (via security)
Windows Certificate Export from Local Certificate Store (Event ID 1007)
Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Windows CAPI2 Event 70: Certificate Private Key Acquired
Pivot detection · T1649 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.