Windows Certificate Export from Local Certificate Store (Event ID 1007)

Flags Windows events where a certificate is exported from the local certificate store via Certificate Services client telemetry.

FreeReviewedSigma · Medium · v2
Product
windows
Service
certificateservicesclient-lifecycle-system
Author
Zach Mathis (SigmaHQ), DRL 1.1
Published
2023-05-13
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies when an application exports a certificate from the local Windows certificate store. Certificate export can enable attackers to move trust material, and in some cases may include private key material, supporting credential access and persistence. The detection relies on Windows certificate services client lifecycle telemetry reporting Event ID 1007 for certificate export activity.

Related detections4 linkedT1649 — drag to rearrange
Suspicious LDAP Enumeration of Certificate Templates (via security)
Windows CAPI2 Event 70: Certificate Private Key Acquired
Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Windows Certificate Export from Local Certificate Store (Event ID 1007)
Pivot detection · T1649 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.