BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
4 BIOCs match the current filters. technique: T1553 ✕
Download CSV Show ATT&CK heatmapManipulation of Crypto Subject Interface Package (SIP) Provider Informational Evasion
Malicious modification of crypto subject interface package (SIP) provider Registry keys can be leveraged to trick the OS into incorrectly validating invalid signing certificates. May have legitimate uses, but check for malicious activity.
Indicator:Registry action type = all AND registry key name = *SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\* , *SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\* , *\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\* , *\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\* Process initiator path != *\microsoft office\root\integration\integrator.exe AND cgo path != *\microsoft office\root\integration\integrator.exe Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Subvert Trust Controls: SIP and Trust Provider Hijacking (T1553.003)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
New certificate added to the trusted root store Informational Evasion
Untrusted certificates could be used to install untrusted drivers and malicious code.
Indicator:Process action type = execution AND target process cmd = *addstore*root* AND target process name = certutil.exe
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Subvert Trust Controls: Install Root Certificate (T1553.004)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Root certificate installed Informational Evasion
Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system.
Indicator:Registry registry key name = *\Software\Microsoft\SystemCertificates*\root\* , *\Software\Microsoft\SystemCertificates*\authroot\* , *\Software\Microsoft\SystemCertificates*\certificationauthority\* , *\Software\Microsoft\Cryptography\Services\ServiceName\SystemCertificates*\root\* , *\Software\Microsoft\Cryptography\Services\ServiceName\SystemCertificates*\authroot\* , *\Software\Microsoft\Cryptography\Services\ServiceName\SystemCertificates*\certificationauthority\* , *\Software\Policy\Microsoft\SystemCertificates*\root\* , *\Software\Policy\Microsoft\SystemCertificates*\authroot\* , *\Software\Policy\Microsoft\SystemCertificates*\certificationauthority\* , *\Software\Microsoft\EnterpriseCertificates*\root\* , *\Software\Microsoft\EnterpriseCertificates*\authroot\* , *\Software\Microsoft\EnterpriseCertificates*\certificationauthority\* AND registry key name != *disallowed* AND *protectedroots AND *certificates AND *crls* AND *ctls AND *autoupdate* AND *appcontainer* AND action type = create_registry_key Process initiated by != svchost.exe AND aexnsagent.exe AND dgwip.exe AND consent.exe AND inteltechnologyaccessservice.exe AND ecagent.exe AND loadstate.exe AND avp.exe AND setupplatform.exe AND cgo name != svchost.exe AND aexnsagent.exe AND dgwip.exe AND consent.exe AND inteltechnologyaccessservice.exe AND ecagent.exe AND loadstate.exe AND avp.exe AND setupplatform.exe Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Subvert Trust Controls: Install Root Certificate (T1553.004)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Root certificate installed Informational Evasion
Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system.
Indicator:Process action type = execution AND target process cmd = *add-trusted-cert* , *update-ca-certificates* , *update-ca-trust*
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Subvert Trust Controls: Install Root Certificate (T1553.004)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11