kevmap

TechniquesT1553 › T1553.004

T1553.004 Install Root Certificate

defense impairment — Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
10
Sigma rules tagged attack.t1553.004
0
KEV CVEs mapped here
<p>Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers. Root certificates are used in public key cryptography to identify a root certificate authority (CA). When a root certificate is installed, the system or application will trust certificates in the root's chain of trust that have been signed by the root certificate. Certificates are commonly used for establishing secure TLS/SSL communications within a web browser. When a user attempts to browse a website that presents a certificate that is not trusted an error message will be displayed to warn the user of the security risk. Depending on the security settings, the browser may not allow the user to establish a connection to the website.</p><p>Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system. Adversaries have used this technique to avoid security warnings prompting users when compromised systems connect over HTTPS to adversary controlled web servers that spoof legitimate websites in order to collect login credentials.</p><p>Atypical root certificates have also been pre-installed on systems by the manufacturer or in the software supply chain and were used in conjunction with malware/adware to provide Adversary-in-the-Middle capability for intercepting information transmitted over secure TLS/SSL communications.</p><p>Root certificates (and their associated chains) can also be cloned and reinstalled. Cloned certificate chains will carry many of the same metadata characteristics of the source and can be used to sign malicious code that may then bypass signature validation tools (ex: Sysinternals, antivirus, etc.) used to block execution and/or uncover artifacts of Persistence.</p><p>In macOS, the Ay MaMi malware uses <code>/usr/bin/security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain /path/to/malicious/cert</code> to install a malicious certificate as a trusted root certificate into the system keychain.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1553.004

Author: frack113 · 2022-12-23 · logsource: product=windows category=process_creation · 114de787-4eb2-48cc-abdb-c0b449f93ea4
Detect use of X509Enrollment
Techniques: T1553.004
Author: Austin Clark · 2019-08-12 (modified 2023-01-04) · logsource: product=cisco service=aaa · 1f978c6a-4415-47fb-aca5-736a44d7ca3d
Show when private keys are being exported from the device, or when new certificates are installed
Techniques: T1553.004T1552.004
Author: oscd.community, @redcanary, Zach Stanford @svch0st · 2020-10-10 (modified 2022-12-02) · logsource: product=windows category=ps_script · 42821614-9264-4761-acfc-5772c3286f76
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Techniques: T1553.004
Author: frack113 · 2022-12-23 · logsource: product=windows category=ps_script · 504d63cb-0dba-4d02-8531-e72981aace2c
Detect use of X509Enrollment
Techniques: T1553.004
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-09-09 (modified 2023-01-16) · logsource: product=windows category=process_creation · 5f6a601c-2ecb-498b-9c33-660362323afa
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Techniques: T1553.004
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-03 (modified 2026-01-01) · logsource: product=linux category=process_creation · 700fb7e8-2981-401c-8430-be58e189e741
Detects installation of suspicious packages using system installation utilities
Techniques: T1553.004
Author: Ömer Günal, oscd.community · 2020-10-05 (modified 2022-07-07) · logsource: product=linux category=process_creation · 78a80655-a51e-4669-bc6b-e9d206a462ee
Detects installation of new certificate on the system which attackers may use to avoid warnings when connecting to controlled web servers or C2s
Techniques: T1553.004
Author: @SerkinValery · 2024-03-07 · logsource: product=windows service=system · 994bfd6d-0a2e-481e-a861-934069fcf5f5
Detects denied requests by Active Directory Certificate Services. Example of these requests denial include issues with permissions on the certificate template or invalid signatures.
Techniques: T1553.004
Author: oscd.community, @redcanary, Zach Stanford @svch0st · 2023-03-05 (modified 2024-03-05) · logsource: product=windows category=process_creation · d2125259-ddea-4c1c-9c22-977eb5b29cf0
Detects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Techniques: T1553.004
Author: oscd.community, @redcanary, Zach Stanford @svch0st · 2023-03-05 · logsource: product=windows category=process_creation · ff992eac-6449-4c60-8c1d-91c9722a1d48
Detects execution of "certmgr" with the "add" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
Techniques: T1553.004

Rules tagged at the parent level (attack.t1553) 4

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Matt Anderson (Huntress) · 2024-07-23 · logsource: product=windows category=process_creation · 0090b851-3543-42db-828c-02fee986ff0b
Detects the use of software that is related to the University of California, Berkeley via metadata information. This indicates it may be related to BOINC software and can be used maliciously if unauthorized.
Techniques: T1553
Author: Matt Anderson (Huntress) · 2024-07-23 · logsource: product=windows category=process_creation · 30d07da2-83ab-45d8-ae75-ec7c0edcaffc
Detects the execution of a renamed BOINC binary.
Techniques: T1553
Author: Tim Rauch (rule), Elastic (idea) · 2022-10-21 (modified 2022-12-28) · logsource: product=macos category=process_creation · 6e4dcdd1-e48b-42f7-b2d8-3b413fc58cb4
Detects when the macOS Script Editor utility spawns an unusual child process.
Author: Florian Roth (Nextron Systems), Maxime Thiebaut · 2021-08-23 (modified 2024-12-01) · logsource: product=windows category=process_creation · a4eaf250-7dc1-4842-862a-5e71cd59a167
Detects a explorer.exe sub process of the RazerInstaller software which can be invoked from the installer to select a different installation folder but can also be exploited to escalate privileges to LOCAL SYSTEM
Techniques: T1553