Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments

Identifies Windows processes running Certify.exe with AD certificate abuse-oriented command line arguments.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
pH-T (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-04-17
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies executions of Certify.exe by matching PE metadata indicators and command-line substrings associated with common Active Directory certificate abuse workflows. Attackers can leverage Certify to enumerate certificate services, identify vulnerable configurations, and request or download certificates using specific parameters. The detection relies on Windows process creation telemetry, including Image/OriginalFileName metadata and CommandLine content.

Related detections4 linkedT1649 — drag to rearrange
Suspicious LDAP Enumeration of Certificate Templates (via security)
Windows Certificate Export from Local Certificate Store (Event ID 1007)
Windows CAPI2 Event 70: Certificate Private Key Acquired
Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Pivot detection · T1649 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.