1200KM / detection
T1553.004 Install Root Certificate — Detection Rules
Detection workspace for T1553.004 Install Root Certificate: 10 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Install Root Certificate · test · low · {"product":"linux","category":"process_creation"}
- Suspicious Package Installed - Linux · test · medium · {"product":"linux","category":"process_creation"}
- Cisco Crypto Commands · test · high · {"product":"cisco","service":"aaa"}
- Active Directory Certificate Services Denied Certificate Enrollment Request · test · low · {"product":"windows","service":"system"}
- Root Certificate Installed - PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Suspicious X509Enrollment - Ps Script · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- New Root Certificate Installed Via CertMgr.EXE · test · medium · {"category":"process_creation","product":"windows"}
- New Root Certificate Installed Via Certutil.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Root Certificate Installed From Susp Locations · test · high · {"category":"process_creation","product":"windows"}
- Suspicious X509Enrollment - Process Creation · test · medium · {"product":"windows","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0056 Detection Strategy for Subvert Trust Controls via Install Root Certificate.
AN0153 Analytic 0153
Detection of unauthorized modifications to Windows root certificate stores by monitoring registry keys, certificate installation processes, and creation of new certificate entries not in baseline trusted lists.
AN0154 Analytic 0154
Detection of unexpected additions or modifications to system-wide certificate stores or execution of commands adding certificates to trusted stores.
AN0155 Analytic 0155
Detection of malicious certificate installation via monitoring execution of the `security add-trusted-cert` command and modifications to system keychains.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.