Detects execution of "certmgr" with the "add" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Read MoreDetects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Read MoreAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Read MoreCisco Crypto Commands
Show when private keys are being exported from the device, or when new certificates are installed
Read MoreAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Read MoreDetects installation of new certificate on the system which attackers may use to avoid warnings when connecting to controlled web servers or C2s
Read More