Windows PFX File Creation via File Write Events
Flags Windows file events where a .pfx (certificate + private key) is created, excluding a few common benign locations.
FreeUnreviewedSigmalowv1
windows-pfx-file-creation-via-file-write-events-dca1b3e8
title: Windows PFX File Creation via File Write Events
id: 243aff18-74ca-4c33-a615-ee5fe46fc43b
status: test
description: This rule identifies creation or write activity for files with a .pfx extension on Windows, which contain certificates and private keys. Attackers may generate or stage PFX bundles to enable certificate-based impersonation or signing with stolen keys. The detection relies on Windows file event telemetry, matching the target filename suffix while excluding common developer and certificate-related directories to reduce noise.
references:
- https://github.com/OTRF/detection-hackathon-apt29/issues/14
- https://github.com/OTRF/ThreatHunter-Playbook/blob/2d4257f630f4c9770f78d0c1df059f891ffc3fec/docs/evals/apt29/detections/6.B.1_6392C9F1-D975-4F75-8A70-433DEDD7F622.md
- https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/file/file_event/file_event_win_pfx_file_creation.yml
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule Team
date: 2020-05-02
modified: 2025-10-19
tags:
- attack.credential-access
- attack.t1552.004
- detection.threat-hunting
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|endswith: .pfx
filter_optional_onedrive:
Image:
- C:\Program Files\Microsoft OneDrive\OneDrive.exe
- C:\Program Files (x86)\Microsoft OneDrive\OneDrive.exe
TargetFilename|endswith: \OneDrive\CodeSigning.pfx
filter_optional_visual_studio:
TargetFilename|startswith:
- C:\Program Files (x86)\Microsoft Visual Studio\
- C:\Program Files\Microsoft Visual Studio\
filter_optional_cmake:
TargetFilename|startswith: C:\Program Files\CMake\
condition: selection and not 1 of filter_optional_*
falsepositives:
- System administrators legitimately managing certificates and PKI infrastructure
- Development environments where developers create test certificates for application signing
- Automated certificate deployment tools and scripts used in enterprise environments
- Software installation processes that include certificate provisioning (e.g., web servers, VPN clients)
- Certificate backup and recovery operations performed by IT staff
- Build systems and CI/CD pipelines that generate code signing certificates
- Third-party applications that create temporary certificates for secure communications
level: low
license: DRL-1.1
related:
- id: dca1b3e8-e043-4ec8-85d7-867f334b5724
type: derived
What it detects
This rule identifies creation or write activity for files with a .pfx extension on Windows, which contain certificates and private keys. Attackers may generate or stage PFX bundles to enable certificate-based impersonation or signing with stolen keys. The detection relies on Windows file event telemetry, matching the target filename suffix while excluding common developer and certificate-related directories to reduce noise.
Known false positives
- System administrators legitimately managing certificates and PKI infrastructure
- Development environments where developers create test certificates for application signing
- Automated certificate deployment tools and scripts used in enterprise environments
- Software installation processes that include certificate provisioning (e.g., web servers, VPN clients)
- Certificate backup and recovery operations performed by IT staff
- Build systems and CI/CD pipelines that generate code signing certificates
- Third-party applications that create temporary certificates for secure communications
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.