Windows Certificate Store
Type: certstore-windows
Category: Certificate Store
Access Mode: AGENT
Produces: certificate, public-key
Reads certificates directly from the Windows Certificate Store using native Windows APIs. Requires the sensor to be running on a Windows machine.
What It Discovers
Section titled “What It Discovers”- All certificates in the specified store locations
- Certificate chains and trust relationships
- Certificate properties (subject, issuer, validity, key usage)
- Public keys associated with stored certificates
Configuration
Section titled “Configuration”storeLocation: LocalMachinestores: - My - Root - CA - TrustConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
storeLocation | string | No | LocalMachine | Store location: LocalMachine or CurrentUser |
stores | string list | No | My, Root, CA, Trust | Store names to scan |
Common Store Names
Section titled “Common Store Names”| Store | Contents |
|---|---|
My | Personal certificates (server certs, client auth certs) |
Root | Trusted Root Certification Authorities |
CA | Intermediate Certification Authorities |
Trust | Enterprise trust certificates |
TrustedPeople | Explicitly trusted end-entity certificates |
TrustedPublisher | Trusted software publishers |
Requirements
Section titled “Requirements”- Sensor must be running on Windows
- No additional configuration or permissions needed for
LocalMachine(runs as the sensor service account) CurrentUserreads the current user’s certificate store
Example Output
Section titled “Example Output”- Certificate: “webserver.corp.example.com” — RSA-2048, My store
- Certificate: “DigiCert Global Root G2” — RSA-2048, Root store
- Certificate: “Corp Internal CA” — EC-384, CA store
- Default config works — Running with no config scans
LocalMachinewith the four standard stores. Good for most cases. - CurrentUser — Use when scanning developer workstations where personal certificates are relevant
- Service account — The sensor’s Windows service account determines what LocalMachine certs are accessible
Related
Section titled “Related”- Filesystem Scanners — Scan certificate files on disk
- Directory Services — Scan AD for published certificates