BIOC
Informational
✕
Root certificate installed
Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Subvert Trust Controls: Install Root Certificate (T1553.004)
Indicator:
Process action type = execution AND target process cmd = *add-trusted-cert* , *update-ca-certificates* , *update-ca-trust*
Preventable: yes