Skip to content

Windows Certificate Store

Type: certstore-windows
Category: Certificate Store
Access Mode: AGENT
Produces: certificate, public-key

Reads certificates directly from the Windows Certificate Store using native Windows APIs. Requires the sensor to be running on a Windows machine.


  • All certificates in the specified store locations
  • Certificate chains and trust relationships
  • Certificate properties (subject, issuer, validity, key usage)
  • Public keys associated with stored certificates

storeLocation: LocalMachine
stores:
- My
- Root
- CA
- Trust
FieldTypeRequiredDefaultDescription
storeLocationstringNoLocalMachineStore location: LocalMachine or CurrentUser
storesstring listNoMy, Root, CA, TrustStore names to scan
StoreContents
MyPersonal certificates (server certs, client auth certs)
RootTrusted Root Certification Authorities
CAIntermediate Certification Authorities
TrustEnterprise trust certificates
TrustedPeopleExplicitly trusted end-entity certificates
TrustedPublisherTrusted software publishers

  • Sensor must be running on Windows
  • No additional configuration or permissions needed for LocalMachine (runs as the sensor service account)
  • CurrentUser reads the current user’s certificate store

  • Certificate: “webserver.corp.example.com” — RSA-2048, My store
  • Certificate: “DigiCert Global Root G2” — RSA-2048, Root store
  • Certificate: “Corp Internal CA” — EC-384, CA store

  • Default config works — Running with no config scans LocalMachine with the four standard stores. Good for most cases.
  • CurrentUser — Use when scanning developer workstations where personal certificates are relevant
  • Service account — The sensor’s Windows service account determines what LocalMachine certs are accessible