Suspicious Certificate Request Pattern via CertReq

Rule Info

Name
Suspicious Certificate Request Pattern via CertReq
Author
Swachchhanda Shrawn Poudel (Nextron Systems)
Description
Detects suspicious certificate request patterns that may indicate abuse of certreq.exe for privilege escalation or lateral movement.
Date
2026-04-27 00:00:00
Modified
None
Id
6b2d372c-43a5-4fa6-b663-de7e3c6c919e
Tags
attack.credential-access attack.privilege-escalation attack.t1649
Type
Nextron Sigma feed only (private)

Rule History