Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures.(Citation: Wikipedia Public Key Crypto) Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc. Adversaries may also look in common key directories, such as ~/.ssh for SSH keys on * nix-based systems or C:\Users\(username)\.ssh\ on Windows. Adversary tools may also search compromised systems for file extensions relating to cryptographic keys and certificates.(Citation: Kaspersky Careto)(Citation: Palo Alto Prince of Persia) When a device is registered to Entra ID, a device key and a transport key are generated and used to verify the device’s identity.(Citation: Microsoft Primary Refresh Token) An adversary with access to the device may be able to export the keys in order to impersonate the device.(Citation: AADInternals Azure AD Device Identities) On network devices, private keys may be exported via [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `crypto pki export`.(Citation: cisco_deploy_rsa_keys) Some private keys require a password or passphrase for operation, so an adversary may also use [Input Capture](https://attack.mitre.org/techniques/T1056) for keylogging or attempt to [Brute Force](https://attack.mitre.org/techniques/T1110) the passphrase off-line. These private keys can be used to authenticate to [Remote Services](https://attack.mitre.org/techniques/T1021) like SSH or for use in decrypting other collected files such as email.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Password Policies
is blocked by Restrict File and Directory Permissions
is blocked by Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms
is blocked by Audit
is blocked by Encrypt Sensitive Information
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Encrypting Data At Rest
is blocked by Public Key Infrastructure (PKI)
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Media & Data Retention
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Identification & Authentication for Organizational Users
is blocked by Authenticator Management
is blocked by Account Management
is blocked by Access Control For Mobile Devices
is blocked by Boundary Protection
is blocked by Remote Access
is blocked by Wireless Networking
is blocked by Information In Shared Resources
is blocked by Secure Software Development Practices (SSDP)
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Vulnerability Scanning
Impressum German English