Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters

Flags Certipy.exe execution on Windows using PE metadata and Certipy-like AD CS command-line arguments.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
pH-T (Nextron Systems), Sittikorn Sangrattanapitak (SigmaHQ), DRL 1.1
Published
2023-04-17
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies executions of Certipy by matching process image characteristics associated with Certipy.exe and by requiring common Certipy command-line keywords and flags related to AD CS enumeration and certificate abuse. Attackers use Certipy to query Active Directory Certificate Services and perform actions such as relaying, requesting, forging, and shadow-related operations. The detection relies on Windows process creation telemetry, including image filename/metadata and full command-line content.

Related detections4 linkedT1649 — drag to rearrange
Suspicious LDAP Enumeration of Certificate Templates (via security)
Windows Certificate Export from Local Certificate Store (Event ID 1007)
Windows CAPI2 Event 70: Certificate Private Key Acquired
Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Pivot detection · T1649 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.