Subvert Trust Controls T1553
Tactic: Defense Impairment
Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.
Events covered
21 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 68 rules share fields, values, and exclusions.
Fields filtered most (51 distinct)
These fields appear most often in rule filters.
Top indicator values (3596 distinct)
These values appear most often in rule predicates.
Exclusions (283 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 28 rules
- Active Directory Certificate Services Denied Certificate Enrollment Request
- Certutil root certificate installation
- Cisco Crypto Commands
- Gatekeeper Bypass via Xattr
- Install Root Certificate
- Kapeka Backdoor Configuration Persistence
- macOS Code Signature Invalidation
- macOS Gatekeeper User Override
- New Root Certificate Installed Via CertMgr.EXE
- New Root Certificate Installed Via Certutil.EXE
- Persistence Via New SIP Provider
- Potential BOINC Software Execution (UC-Berkeley Signature)
- Potential Secure Deletion with SDelete
- Renamed BOINC Client Execution
- Root Certificate Installed - PowerShell
- Root Certificate Installed From Susp Locations
- Suspicious Execution via macOS Script Editor
- Suspicious Invoke-Item From Mount-DiskImage
- Suspicious Mount-DiskImage
- Suspicious Package Installed - Linux
- Suspicious RazerInstaller Explorer Subprocess
- Suspicious SIP or trust provider registration
- Suspicious Unblock-File
- Suspicious X509Enrollment - Process Creation
- Suspicious X509Enrollment - Ps Script
- Windows AppX Deployment Full Trust Package Installation
- Windows AppX Deployment Unsigned Package Installation
- Windows MSIX Package Support Framework AI_STUBS Execution
Elastic 25 rules
- Attempt to Disable Gatekeeper
- Attempt to Install Root Certificate
- Code Signing Policy Modification Through Built-in tools
- Code Signing Policy Modification Through Registry
- Creation or Modification of Root Certificate
- Expired or Revoked Driver Loaded
- Gatekeeper Override and Execution
- Mark-of-the-Web Removal by an Unusual Process
- Potential Masquerading as System32 DLL
- Potential Masquerading as System32 Executable
- Potential Payload Download via AppleScript Applet
- Quarantine Attrib Removed by Unsigned or Untrusted Process
- Quarantine Attribute Deleted via Untrusted Binary
- Quarantine Attribute Removal via TextEdit
- Quarantine Cleared via Xattr Followed by Ad-hoc Codesign
- Root Certificate Installation
- SIP Provider Modification
- SSL Certificate Deletion
- Suspicious Curl from macOS Application
- Suspicious Execution via Script Editor
- Suspicious File Quarantine Removal via Find
- Suspicious Kernel Feature Activity
- Suspicious Outbound Network Connection via Unsigned Binary
- Suspicious Stop of TCCD via Launchctl
- Windows CryptoAPI Spoofing Vulnerability (CVE-2020-0601 - CurveBall)
Splunk 13 rules
- Certutil Root Certificate Install (Windows Event Log)
- ISO Image Mounted - Windows (PowerShell)
- ISO Image Mounted - Windows (Windows Event Log)
- MacOS Gatekeeper Bypass
- Windows Advanced Installer MSIX with AI_STUBS Execution
- Windows AppX Deployment Full Trust Package Installation
- Windows AppX Deployment Unsigned Package Installation
- Windows Developer-Signed MSIX Package Installation
- Windows Mark Of The Web Bypass
- Windows Registry Certificate Added
- Windows Registry SIP Provider Modification
- Windows SIP Provider Inventory
- Windows SIP WinVerifyTrust Failed Trust Validation