1200KM / detection
T1552.004 Private Keys — Detection Rules
Detection workspace for T1552.004 Private Keys: 6 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Cisco Crypto Commands · test · high · {"product":"cisco","service":"aaa"}
- DPAPI Backup Keys And Certificate Export Activity IOC · test · high · {"product":"windows","category":"file_event"}
- Certificate Exported Via PowerShell - ScriptBlock · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Certificate Exported Via PowerShell · test · medium · {"product":"windows","category":"process_creation"}
- PowerShell Get-Process LSASS · test · high · {"category":"process_creation","product":"windows"}
- Private Keys Reconnaissance Via CommandLine Tools · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0549 Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms
AN1516 Analytic 1516
A process (non-system or user-initiated) accesses private key files in user profile paths or system certificate stores followed by potential network connections or compression activity.
AN1517 Analytic 1517
User or script-based access to ~/.ssh or other directories containing private keys followed by unusual shell activity or network connections.
AN1518 Analytic 1518
Access to user private key directories (e.g., /Users/*/.ssh) via Terminal, scripting engines, or non-default processes.
AN1519 Analytic 1519
CLI-based export of private key material (e.g., 'crypto pki export') with anomalous user session or AAA role escalation.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.