This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Root Certificate Installed From Susp Locations
Original Source:
[Sigma source]
Title:
Root Certificate Installed From Susp Locations
Status:
test
Description:
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
References:
-https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations/
-https://learn.microsoft.com/en-us/powershell/module/pki/import-certificate?view=windowsserver2022-ps
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-09-09
modified:
2023-01-16
Tags:
-'attack.defense-impairment'
-'attack.t1553.004'
Logsource:
category: process_creation
product: windows
Detection:
selection:
CommandLine|contains|all
:
-'Import-Certificate'
-' -FilePath '
-'Cert:\LocalMachine\Root'
CommandLine|contains
:
-'\AppData\Local\Temp\'
-':\Windows\TEMP\'
-'\Desktop\'
-'\Downloads\'
-'\Perflogs\'
-':\Users\Public\'
condition
:
selection
Falsepositives:
-Unlikely
Level:
high