{"id":"T1036.001","name":"Invalid Code Signature","url":"https://attack.mitre.org/techniques/T1036/001","tactics":["stealth"],"platforms":["macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0031","stix_id":"x-mitre-detection-strategy--fbf8f0b2-3587-45c3-be8d-d495384075be","name":"Invalid Code Signature Execution Detection via Metadata and Behavioral Context","url":"https://attack.mitre.org/detectionstrategies/DET0031","analytics":[{"id":"AN0089","stix_id":"x-mitre-analytic--bf6b3f42-a7a5-4e6d-840a-e892aa74916c","name":"Analytic 0089","description":"Execution of binaries with invalid digital signatures, where metadata claims code is signed but validation fails. Behavior is often correlated with suspicious parent processes or unexpected execution paths.","url":"https://attack.mitre.org/detectionstrategies/DET0031#AN0089","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Windows Defender","channel":"Operational log","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-windows-defender"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"SignatureValidationResult","description":"Allow tuning to include 'invalid', 'expired', or 'untrusted root' based on environment tolerance"},{"field":"ParentProcessName","description":"Helps tune false positives by limiting to suspicious parent process executions"},{"field":"TimeWindow","description":"Defines correlation window between metadata check and process execution"}],"live":true,"detection_strategies":["DET0031"],"techniques":["T1036.001"]},{"id":"AN0090","stix_id":"x-mitre-analytic--35d9b6e6-aed8-4e9e-b6ee-e683d9c17fd0","name":"Analytic 0090","description":"Binaries or applications executed with tampered or unverifiable code signatures. Often tied to Gatekeeper bypasses, App Translocation, or use of unsigned launch daemons by untrusted users.","url":"https://attack.mitre.org/detectionstrategies/DET0031#AN0090","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"subsystem:syspolicyd","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"fs:fileevents","channel":"/var/log/install.log","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"fs-fileevents"}],"mutable_elements":[{"field":"CodeSigningStatus","description":"Filters such as 'Unsigned', 'NotTrusted', or 'ModifiedSinceSigning' may vary by policy enforcement level"},{"field":"UserContext","description":"Tune whether detection applies to all users or excludes trusted admin accounts"},{"field":"ExecutablePathPrefix","description":"Enable tuning for known valid locations (e.g., /Applications) vs. suspicious paths (/Users/Shared)"}],"live":true,"detection_strategies":["DET0031"],"techniques":["T1036.001"]}],"live":true,"version":"1.0","techniques":["T1036.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}