BIOC
Informational
✕
Tampering with Windows certificate blocking configuration
Adding subkeys of the certificates to block disallows a security vendor's certificate on the affected computer, so that Windows would not allow the program to run.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
Indicator:
Registry action type = create_registry_key , set_registry_value AND registry key name = *SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates* Host host os = windows
Preventable: yes