{"id":"T1553.004","name":"Install Root Certificate","url":"https://attack.mitre.org/techniques/T1553/004","tactics":["defense-impairment"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0056","stix_id":"x-mitre-detection-strategy--d9e95391-5ea4-49af-a525-31655a72e470","name":"Detection Strategy for Subvert Trust Controls via Install Root Certificate.","url":"https://attack.mitre.org/detectionstrategies/DET0056","analytics":[{"id":"AN0153","stix_id":"x-mitre-analytic--a65545d7-fa1b-4d6f-b19c-fa03862c6210","name":"Analytic 0153","description":"Detection of unauthorized modifications to Windows root certificate stores by monitoring registry keys, certificate installation processes, and creation of new certificate entries not in baseline trusted lists.","url":"https://attack.mitre.org/detectionstrategies/DET0056#AN0153","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=12","data_component":"DC0056","data_component_name":"Windows Registry Key Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TrustedRootHashList","description":"Baseline list of root certificate hashes; defenders can tune based on organizational certificate policies."},{"field":"MonitoredProcesses","description":"Processes associated with certificate management that should be flagged if executed by non-admin users or in unusual contexts."},{"field":"TimeWindow","description":"Correlation window for registry modifications, certificate installation, and process creation to strengthen detection."}],"live":true,"detection_strategies":["DET0056"],"techniques":["T1553.004"]},{"id":"AN0154","stix_id":"x-mitre-analytic--759c073c-2c40-484b-af47-8426ec5d5a3e","name":"Analytic 0154","description":"Detection of unexpected additions or modifications to system-wide certificate stores or execution of commands adding certificates to trusted stores.","url":"https://attack.mitre.org/detectionstrategies/DET0056#AN0154","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, write: File modifications under /etc/ssl/certs, /usr/local/share/ca-certificates, or /etc/pki/ca-trust/source/anchors","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"execve: Execution of update-ca-certificates or trust anchor modification commands","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"CertificatePaths","description":"Paths monitored for certificate modifications; can be tuned depending on Linux distribution."},{"field":"AdminAccounts","description":"Expected user accounts with privileges to install root certificates; anomalies outside this context are suspicious."}],"live":true,"detection_strategies":["DET0056"],"techniques":["T1553.004"]},{"id":"AN0155","stix_id":"x-mitre-analytic--477fb167-a388-4e85-856b-bdcb36e7fd95","name":"Analytic 0155","description":"Detection of malicious certificate installation via monitoring execution of the `security add-trusted-cert` command and modifications to system keychains.","url":"https://attack.mitre.org/detectionstrategies/DET0056#AN0155","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of /usr/bin/security add-trusted-cert or keychain modifications to System.keychain","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"query: Enumeration of root certificates showing unexpected additions","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"MonitoredCommands","description":"Commands related to certificate management (e.g., security, profiles) that can be tuned per environment."},{"field":"KeychainBaseline","description":"Baseline of expected certificates in System.keychain to reduce false positives from legitimate enterprise certificates."}],"live":true,"detection_strategies":["DET0056"],"techniques":["T1553.004"]}],"live":true,"version":"1.0","techniques":["T1553.004"]}],"sigma_rules":[{"id":"114de787-4eb2-48cc-abdb-c0b449f93ea4","title":"Suspicious X509Enrollment - Process Creation","author":"frack113","status":"test","level":"medium","date":"2022-12-23","modified":null,"description":"Detect use of X509Enrollment","references":["https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=42","https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=41","https://learn.microsoft.com/en-us/dotnet/api/microsoft.hpc.scheduler.store.cx509enrollmentwebclassfactoryclass?view=hpc-sdk-5.1.6115"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1553.004"],"path":"rules/windows/process_creation/proc_creation_win_powershell_x509enrollment.yml","techniques":["T1553.004"],"cves":[]},{"id":"1f978c6a-4415-47fb-aca5-736a44d7ca3d","title":"Cisco Crypto Commands","author":"Austin Clark","status":"test","level":"high","date":"2019-08-12","modified":"2023-01-04","description":"Show when private keys are being exported from the device, or when new certificates are installed","references":["https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-a1-cr-book_chapter_0111.html"],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.credential-access","attack.defense-impairment","attack.t1553.004","attack.t1552.004"],"path":"rules/network/cisco/aaa/cisco_cli_crypto_actions.yml","techniques":["T1553.004","T1552.004"],"cves":[]},{"id":"42821614-9264-4761-acfc-5772c3286f76","title":"Root Certificate Installed - PowerShell","author":"oscd.community, @redcanary, Zach Stanford @svch0st","status":"test","level":"medium","date":"2020-10-10","modified":"2022-12-02","description":"Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1553.004/T1553.004.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1553.004"],"path":"rules/windows/powershell/powershell_script/posh_ps_root_certificate_installed.yml","techniques":["T1553.004"],"cves":[]},{"id":"504d63cb-0dba-4d02-8531-e72981aace2c","title":"Suspicious X509Enrollment - Ps Script","author":"frack113","status":"test","level":"medium","date":"2022-12-23","modified":null,"description":"Detect use of X509Enrollment","references":["https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=42","https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=41","https://learn.microsoft.com/en-us/dotnet/api/microsoft.hpc.scheduler.store.cx509enrollmentwebclassfactoryclass?view=hpc-sdk-5.1.6115"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1553.004"],"path":"rules/windows/powershell/powershell_script/posh_ps_x509enrollment.yml","techniques":["T1553.004"],"cves":[]},{"id":"5f6a601c-2ecb-498b-9c33-660362323afa","title":"Root Certificate Installed From Susp Locations","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-09-09","modified":"2023-01-16","description":"Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.","references":["https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations/","https://learn.microsoft.com/en-us/powershell/module/pki/import-certificate?view=windowsserver2022-ps"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1553.004"],"path":"rules/windows/process_creation/proc_creation_win_powershell_import_cert_susp_locations.yml","techniques":["T1553.004"],"cves":[]},{"id":"700fb7e8-2981-401c-8430-be58e189e741","title":"Suspicious Package Installed - Linux","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-01-03","modified":"2026-01-01","description":"Detects installation of suspicious packages using system installation utilities","references":["https://gist.githubusercontent.com/MichaelKoczwara/12faba9c061c12b5814b711166de8c2f/raw/e2068486692897b620c25fde1ea258c8218fe3d3/history.txt"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1553.004"],"path":"rules/linux/process_creation/proc_creation_lnx_install_suspicious_packages.yml","techniques":["T1553.004"],"cves":[]},{"id":"78a80655-a51e-4669-bc6b-e9d206a462ee","title":"Install Root Certificate","author":"Ömer Günal, oscd.community","status":"test","level":"low","date":"2020-10-05","modified":"2022-07-07","description":"Detects installation of new certificate on the system which attackers may use to avoid warnings when connecting to controlled web servers or C2s","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1553.004/T1553.004.md"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1553.004"],"path":"rules/linux/process_creation/proc_creation_lnx_install_root_certificate.yml","techniques":["T1553.004"],"cves":[]},{"id":"994bfd6d-0a2e-481e-a861-934069fcf5f5","title":"Active Directory Certificate Services Denied Certificate Enrollment Request","author":"@SerkinValery","status":"test","level":"low","date":"2024-03-07","modified":null,"description":"Detects denied requests by Active Directory Certificate Services.\nExample of these requests denial include issues with permissions on the certificate template or invalid signatures.\n","references":["https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd299871(v=ws.10)","https://www.gradenegger.eu/en/details-of-the-event-with-id-53-of-the-source-microsoft-windows-certificationauthority/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.defense-impairment","attack.t1553.004"],"path":"rules/windows/builtin/system/microsoft_windows_certification_authority/win_system_adcs_enrollment_request_denied.yml","techniques":["T1553.004"],"cves":[]},{"id":"d2125259-ddea-4c1c-9c22-977eb5b29cf0","title":"New Root Certificate Installed Via Certutil.EXE","author":"oscd.community, @redcanary, Zach Stanford @svch0st","status":"test","level":"medium","date":"2023-03-05","modified":"2024-03-05","description":"Detects execution of \"certutil\" with the \"addstore\" flag in order to install a new certificate on the system.\nAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1553.004/T1553.004.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1553.004"],"path":"rules/windows/process_creation/proc_creation_win_certutil_certificate_installation.yml","techniques":["T1553.004"],"cves":[]},{"id":"ff992eac-6449-4c60-8c1d-91c9722a1d48","title":"New Root Certificate Installed Via CertMgr.EXE","author":"oscd.community, @redcanary, Zach Stanford @svch0st","status":"test","level":"medium","date":"2023-03-05","modified":null,"description":"Detects execution of \"certmgr\" with the \"add\" flag in order to install a new certificate on the system.\nAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1553.004/T1553.004.md","https://securelist.com/to-crypt-or-to-mine-that-is-the-question/86307/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1553.004"],"path":"rules/windows/process_creation/proc_creation_win_certmgr_certificate_installation.yml","techniques":["T1553.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}