1200KM / simulation
T1553.004 Install Root Certificate — Attack Simulation
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers. Root certificates are used in public key cryptography to identify a root certificate authority (CA). When a root certificate is installed, the system or application will trust certificates in the root's chain of trust that have been signed by the root certificate. Certificates are commonly used for…
Technique description
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers. Root certificates are used in public key cryptography to identify a root certificate authority (CA). When a root certificate is installed, the system or application will trust certificates in the root's chain of trust that have been signed by the root certificate. Certificates are commonly used for…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Install root CA on Debian/Ubuntu
Procedure 53bcf8a0-1549-4b85-b919-010c56d724ff; elevation required; cleanup not declared. Not executed or individually validated.
- Install root CA on Windows with certutil
Procedure 5fdb1a7a-a93c-4fbe-aa29-ddd9ef94ed1f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Install root CA on Windows
Procedure 76f49d86-5eb1-461a-a032-a480f86652f1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Install root CA on CentOS/RHEL
Procedure 9c096ec4-fd42-419d-a762-d64cc950627e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add Root Certificate to CurrentUser Certificate Store
Procedure ca20a3f1-42b5-4e21-ad3f-1049199ec2e0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Install root CA on macOS
Procedure cc4a0b8c-426f-40ff-9426-4e10e5bf4c49; elevation required; cleanup not declared. Not executed or individually validated.
- Install root CA on FreeBSD
Procedure f4568003-1438-44ab-a234-b3252ea7e7a3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.