BIOC Informational

Root certificate installed

Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Subvert Trust Controls: Install Root Certificate (T1553.004)
Indicator:

Process action type = execution AND target process cmd = *add-trusted-cert* , *update-ca-certificates* , *update-ca-trust*

Preventable: yes