Subvert Trust Controls T1553

Tactic: Defense Impairment

Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain mechanisms to identify programs or websites as possessing some level of trust. Examples of such features would include a program being allowed to run because it is signed by a valid code signing certificate, a program prompting the user with a warning because it has an attribute set from being downloaded from the Internet, or getting an indication that you are about to connect to an untrusted site.

Events covered

21 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 68 rules share fields, values, and exclusions.

Fields filtered most (51 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
event.type17eq 15, in 2start, change, deletion, process_started
host.os.type17eq 17
Image15ends_with 9, eq 2, is_not_null 2, contains 1, in 1, starts_with 1\certutil.exe, *\\ai_stubs\\aistubx64.exe, *\\ai_stubs\\aistubx64elevated.exe, *\\ai_stubs\\aistubx86.exe, /apt
process_name15eq 10, in 5, starts_with 2, wildcard 2bash, curl, csh, nscurl, agentactivationruntimestarter.exe
EventType14eq 12, in 2exec, extended_attributes_delete, ProcessRollup2, cs_invalidated, exec_event
CommandLine9contains 9com.apple.quarantine, root, -filepath , nc, --install
process.args9eq 7, in 3, contains 2, ends_with 2, regex_match 1, wildcard 1-c, -*a*, --deep, --directory, --download
EventID8eq 7, in 123, 26, 400, 4103, 4104
OriginalFileName6eq 6popupwrapper.exe, bcdedit.exe, boinc.exe, certmgt.exe, certutil.exe
Details5contains 2, eq 2, ends_with 1.dll, (empty), 0, 0x00000000, 0x00000001
ScriptBlockText5contains 5-imagepath , ):\, -path , .driveletter, 884e2002-217d-11da-b2a4-000e7bbb2b09
TargetFilename5ends_with 2, regex_match 1, starts_with 1, wildcard 1(?i)\x5cdevice\x5ccdrom, .exe:zone.identifier, .exe:zone.identifier:$data, .msi:zone.identifier, /applications/*
TargetObject5contains 3, wildcard 2, ends_with 1*\software\microsoft\cryptography\oid\encodingtype..., *\software\microsoft\cryptography\providers\trust\finalpo..., *\software\wow6432node\microsoft\cryptography\oid\encodin..., \$dll, \cryptsipdll
registry_value_name5eq 4, in 1$dll, blob, dll, behavioronfailedverify
ParentImage4ends_with 2, eq 1, is_not_null 1/script editor, /system/applications/utilities/script..., \razerinstaller.exe

Top indicator values (3596 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
101078
event.typeeq
change
394
event.typeeq
deletion
216
EventTypeeq
exec
6576
EventTypeeq
extended_attributes_delete
33
process.argseq
-c
4107
process.argseq
-d
212
process.argseq
com.apple.quarantine
23
process.code_signature.existseq
false
3119
process.code_signature.trustedeq
false
3115
CommandLinecontains
com.apple.quarantine
22
CommandLinecontains
root
23
EventTypein
exec
2201
Flagseq
8388608
22
HasFullTrusteq
true
22
Imageends_with
/xattr
22
Imageends_with
\certutil.exe
244
OriginalFileNameeq
popupwrapper.exe
22
ScriptBlockTextcontains
-imagepath
22
ScriptBlockTextcontains
mount-diskimage
22
TargetObjectcontains
\software\microsoft\cryptography\oid\encodingtype
22
TargetObjectcontains
\software\microsoft\cryptography\providers\
22
TargetObjectcontains
\software\wow6432node\microsoft\cryptography\oid\encodingtype
22
TargetObjectcontains
\software\wow6432node\microsoft\cryptography\providers\
22
event.typein
process_started
239
event.typein
start
241
parent_process_namewildcard
bash
215
parent_process_namewildcard
osascript
212
parent_process_namewildcard
sh
215
parent_process_namewildcard
zsh
215

Exclusions (283 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Detailseq
mso.dll
2
Imagestarts_with
/opt/homebrew/
2
Imagewildcard
?:\windows\ccm\ccmexec.exe
2
process.Ext.effective_parent.executablein
/Applications/iTerm.app/Contents/MacOS/iTerm2
2
process.code_signature.trustedeq
true
2
CallingProcessstarts_with
svchost.exe,AppReadiness
1
CallingProcessstarts_with
sysprep.exe
1
CommandLinecontains
drop_caches
1
CurrentDirectoryeq
/var/lib/rancher
1
DestinationPortin
22
1
DestinationPortin
25
1
DestinationPortin
443
1
DestinationPortin
465
1
DestinationPortin
53
1
DestinationPortin
587
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 28 rules

Elastic 25 rules

Splunk 13 rules

Kusto 1 rule

Panther 1 rule