1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1552.004 Private Keys — Detection Rules

Detection workspace for T1552.004 Private Keys: 6 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0549 Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms

AN1516 Analytic 1516

A process (non-system or user-initiated) accesses private key files in user profile paths or system certificate stores followed by potential network connections or compression activity.

AN1517 Analytic 1517

User or script-based access to ~/.ssh or other directories containing private keys followed by unusual shell activity or network connections.

AN1518 Analytic 1518

Access to user private key directories (e.g., /Users/*/.ssh) via Terminal, scripting engines, or non-default processes.

AN1519 Analytic 1519

CLI-based export of private key material (e.g., 'crypto pki export') with anomalous user session or AAA role escalation.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1552.004 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.