MITRE ATT&CK technique
Subvert Trust Controls detection rulesT1553
Subvert Trust Controls (T1553) is a MITRE ATT&CK technique in the Defense Impairment tactic. This page lists the 24 community-maintained Sigma detection rules in the library mapped to T1553 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, macos, linux.
Tactic
Cisco Crypto Commands
highShow when private keys are being exported from the device, or when new certificates are installed
cisco
Root Certificate Installed From Susp Locations
highAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · process_creation
Suspicious RazerInstaller Explorer Subprocess
highDetects a explorer.exe sub process of the RazerInstaller software which can be invoked from the installer to select a different installation folder but can also be exploited to escalate privileges to LOCAL SYSTEM
windows · process_creation
Kapeka Backdoor Configuration Persistence
mediumDetects registry set activity of a value called "Seed" stored in the "\Cryptography\Providers\" registry key. The Kapeka backdoor leverages this location to register a new SIP provider for backdoor configuration persistence.
windows · registry_set
New Root Certificate Installed Via CertMgr.EXE
mediumDetects execution of "certmgr" with the "add" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · process_creation
New Root Certificate Installed Via Certutil.EXE
mediumDetects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · process_creation
Persistence Via New SIP Provider
mediumDetects when an attacker register a new SIP provider for persistence and defense evasion
windows · registry_set
Potential Secure Deletion with SDelete
mediumDetects files that have extensions commonly seen while SDelete is used to wipe files.
windows
Renamed BOINC Client Execution
mediumDetects the execution of a renamed BOINC binary.
windows · process_creation
Root Certificate Installed - PowerShell
mediumAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · ps_script
Suspicious Execution via macOS Script Editor
mediumDetects when the macOS Script Editor utility spawns an unusual child process.
macos · process_creation
Suspicious Invoke-Item From Mount-DiskImage
mediumAdversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.
windows · ps_script
Suspicious Package Installed - Linux
mediumDetects installation of suspicious packages using system installation utilities
linux · process_creation
Suspicious Unblock-File
mediumRemove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet.
windows · ps_script
Suspicious X509Enrollment - Process Creation
mediumDetect use of X509Enrollment
windows · process_creation
Suspicious X509Enrollment - Ps Script
mediumDetect use of X509Enrollment
windows · ps_script
Windows AppX Deployment Full Trust Package Installation
mediumDetects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
windows
Windows AppX Deployment Unsigned Package Installation
mediumDetects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events
windows
Active Directory Certificate Services Denied Certificate Enrollment Request
lowDetects denied requests by Active Directory Certificate Services. Example of these requests denial include issues with permissions on the certificate template or invalid signatures.
windows
Gatekeeper Bypass via Xattr
lowDetects macOS Gatekeeper bypass via xattr utility
macos · process_creation
Install Root Certificate
lowDetects installation of new certificate on the system which attackers may use to avoid warnings when connecting to controlled web servers or C2s
linux · process_creation
Suspicious Mount-DiskImage
lowAdversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.
windows · ps_script
Windows MSIX Package Support Framework AI_STUBS Execution
lowDetects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.
windows · process_creation
Potential BOINC Software Execution (UC-Berkeley Signature)
informationalDetects the use of software that is related to the University of California, Berkeley via metadata information. This indicates it may be related to BOINC software and can be used maliciously if unauthorized.
windows · process_creation