1200KM / simulation
T1552.004 Private Keys — Attack Simulation
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc. Adversaries may also look in common key directories, such as ~/.ssh for SSH keys on * nix-based…
Technique description
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc. Adversaries may also look in common key directories, such as ~/.ssh for SSH keys on * nix-based…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Copy Private SSH Keys with CP (freebsd)
Procedure 12e4a260-a7fd-4ed8-bf18-1a28c1395775; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Export Certificates with Mimikatz
Procedure 290df60e-4b5d-4a5e-b0c7-dc5348ea0c86; elevation required; cleanup not declared. Not executed or individually validated.
- Copy the users GnuPG directory with rsync
Procedure 2a5a0601-f5fb-4e2e-aa09-73282ae6afca; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- CertUtil ExportPFX
Procedure 336b25bf-4514-4684-8924-474974f28137; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Find WireGuard configuration files
Procedure 42c55554-3dcb-4df6-8fbb-c8ccacc478d4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Discover Private SSH Keys
Procedure 46959285-906d-40fa-9437-5a439accd878; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Private Keys
Procedure 520ce462-7ca7-441e-b5a5-f8347f632696; elevation required; cleanup not declared. Not executed or individually validated.
- Find TLS private key files
Procedure 5e417277-0ae7-4ad5-a3e8-0fa27c122b29; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Export Root Certificate with Export-PFXCertificate
Procedure 7617f689-bbd8-44bc-adcd-6f8968897848; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Export Root Certificate with Export-Certificate
Procedure 78b274f8-acb0-428b-b1f7-7b0d0e73330a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- ADFS token signing and encryption certificates theft - Local
Procedure 78e95057-d429-4e66-8f82-0f060c1ac96f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Copy Private SSH Keys with CP
Procedure 7c247dc7-5128-4643-907b-73a76d9135c3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Copy Private SSH Keys with rsync
Procedure 864bb0b2-6bb5-489a-b43b-a77b3a16d68a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Copy Private SSH Keys with rsync (freebsd)
Procedure 922b1080-0b95-42b0-9585-b9a5ea0af044; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Copy the users GnuPG directory with rsync (freebsd)
Procedure b05ac39b-515f-48e9-88e9-2f141b5bcad0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- ADFS token signing and encryption certificates theft - Remote
Procedure cab413d8-9e4a-4b8d-9b84-c985bd73a442; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Enumerate WireGuard interface credentials with wg showconf
Procedure e7568442-1b7d-4380-a933-b269d1326b6c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.