BIOC
Informational
✕
New certificate added to the trusted root store
Untrusted certificates could be used to install untrusted drivers and malicious code.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Subvert Trust Controls: Install Root Certificate (T1553.004)
Indicator:
Process action type = execution AND target process cmd = *addstore*root* AND target process name = certutil.exe
Preventable: yes