Manipulation of Crypto Subject Interface Package (SIP) Provider
Malicious modification of crypto subject interface package (SIP) provider Registry keys can be leveraged to trick the OS into incorrectly validating invalid signing certificates. May have legitimate uses, but check for malicious activity.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Evasion
- Status:
- Enabled
Registry action type = all AND registry key name = *SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\* , *SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\* , *\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\* , *\SOFTWARE\WOW6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\* Process initiator path != *\microsoft office\root\integration\integrator.exe AND cgo path != *\microsoft office\root\integration\integrator.exe Host host os = windows
Preventable: yes