{
  "node_id": "mitre-attack-t1649-steal-or-forge-authentication-certificates",
  "title": "MITRE ATT&CK T1649: Steal or Forge Authentication Certificates (Enterprise Tactic TA0006 - Credential Access)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1649 (Steal or Forge Authentication Certificates) is an Enterprise Credential Access technique. Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital certificates are often used to sign and encrypt messages and/or files. Certificates are also used as authentication material. For example, Entra ID device certificates and Active Directory Certificate Services (AD CS) certificates bind to an identity and can be used as credentials for domain accounts. Authentication certificates can be both stolen and forged. Affected platforms: Windows, Linux, macOS, Identity Provider. MITRE-documented mitigations include M1015 Active Directory Configuration, M1042 Disable or Remove Feature or Program, M1041 Encrypt Sensitive Information, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls IA-02, IA-05, IA-13.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 7
}