LoFP LoFP / t1552.004

t1552.004

TitleTags
false positives may be generated based on an automated process or service that exports certificates on the regular. review is required before setting to alert. monitor for abnormal processes performing an export.
it is possible administrators or scripts may run these commands, filtering may be required.
legitimate certificate exports by administrators. additional filters might be required.
not commonly run by administrators. also whitelist your known good certificates
system administrators managing certificates.