BIOC Informational

New certificate added to the trusted root store

Untrusted certificates could be used to install untrusted drivers and malicious code.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Subvert Trust Controls: Install Root Certificate (T1553.004)
Indicator:

Process action type = execution AND target process cmd = *addstore*root* AND target process name = certutil.exe

Preventable: yes